BGP Hijack Used to Push Malicious Update, Granting Attackers Root Access to Servers
Virtualizor, a widely used virtualization management platform, has confirmed that attackers exploited a Border Gateway Protocol (BGP) hijack to redirect legitimate update traffic from Softaculous, the service that distributes Virtualizor's software updates. By diverting this traffic, the attackers were able to slip a malicious version of the Virtualizor package onto some installations instead of the genuine update.
The tampered package reportedly gave attackers persistent root access to compromised systems, the highest level of control available on a server. One hosting provider reported that 5 out of 34 Virtualizor hypervisors it checked showed signs of root-level compromise. The malicious activity is believed to have occurred over a window beginning around August 28.
BGP hijacks are a known but relatively rare attack technique that manipulates how internet traffic is routed, allowing attackers to intercept or redirect data meant for legitimate destinations. When combined with software update mechanisms, this type of attack can be especially dangerous because it exploits the trust businesses place in automatic updates from their vendors.