ThreatCluster

BGP Hijacking Delivers Malicious Virtualizor Updates to Servers

First seen 1 Sep 2026, 09:29 UTC CybersecuritynewsGbhackers 61

Article Content

Browse articles
ThreatCluster

A BGP hijacking incident targeted Softaculous infrastructure, redirecting traffic for Virtualizor update services to attacker-controlled systems. This allowed the delivery of a malicious update package to a limited number of servers, specifically affecting the IP range 162.55.80.0/24 hosted by Hetzner. The attack occurred between 20:57 UTC on August 28 and 06:10 UTC on August 29, 2026. Virtualizor is widely used by hosting providers to manage VPS nodes across various virtualization technologies. The incident has raised concerns among users of the affected systems regarding the integrity of their updates and potential vulnerabilities introduced by the malicious package. The full scope of the impact and the number of affected servers remain unclear, but reports indicate that only a small number were compromised. Security teams are advised to monitor their systems for unusual activity related to Virtualizor updates.

Key Points: • BGP hijacking redirected Virtualizor update traffic to attackers. • Malicious updates affected servers in the IP range 162.55.80.0/24. • The attack occurred from August 28 to August 29, 2026.

Timeline

2026-08-28
BGP hijacking initiated
Attackers redirected traffic for Virtualizor updates to their own systems, starting at 20:57 UTC.
Gbhackers
2026-08-29
Malicious updates delivered
The hijacked traffic allowed the delivery of a poisoned update package to affected servers until 06:10 UTC.
Gbhackers
Recent
Incident reported
Softaculous issued a vendor incident report confirming the BGP hijacking and its implications.
Cybersecuritynews