Hackers Hijack Internet Routing to Push Fake Virtualizor Update
A threat actor exploited a technique known as BGP hijacking to intercept legitimate network traffic and redirect it to servers delivering a malicious update for Virtualizor, a server virtualization control panel from Softaculous. BGP, or Border Gateway Protocol, is the system that routes internet traffic between networks; when attackers manipulate it, they can silently reroute traffic meant for a trusted destination to one under their control.
What made this attack particularly convincing is that the attackers used a technically valid TLS certificate tied to Softaculous' own domains. This meant users attempting to reach legitimate update servers may have seen no obvious warning signs, such as certificate errors, that would typically indicate something was wrong. As a result, systems could have been tricked into downloading and installing a compromised update believing it came from a trusted source.
This incident highlights a growing concern in the cybersecurity world: attacks that target the fundamental infrastructure of the internet rather than individual devices or applications. Because BGP hijacking happens at the network routing level, it can be difficult for end users or even IT teams to detect, and it can affect anyone relying on the targeted software's update mechanism, regardless of their own security posture.