SECURITY Signal 124
BGP hijack of Softaculous IP space delivered malicious Virtualizor updates with valid TLS certificates
Illustration only Photo by Alp Duran on Unsplash
A BGP hijack of Softaculous's 162.55.80.0/24 block at Hetzner diverted traffic to an attacker who obtained valid Let's Encrypt certificates and pushed malicious Virtualizor update packages to a small number of servers.
The attacker bypassed TLS validation by hijacking the certificate authority's domain-ownership check, so affected clients saw no warnings. Softaculous cannot produce a definitive list of affected servers because malicious responses were served directly by the attacker and never reached their logs, meaning every Virtualizor operator must self-check.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
AS62390 (NexonHost) announced 162.55.80.0/24 without authorization via AS6204 (Zet.net), overriding Hetzner's legitimate /16 route with a more specific /24.
The attacker obtained valid Let's Encrypt TLS certificates for virtualizor.com and related domains because the CA's automated domain validation was also routed through the hijack.
A malicious Virtualizor update package was delivered to a small number of installations that checked for updates during the diversion, but no definitive list of affected servers exists.
THE CLUSTER