Hackers Exploit BGP Hijack to Distribute Malicious Virtualizor Update
A coordinated cyber‑attack has succeeded in delivering a compromised update to the Virtualizor virtual‑private‑server (VPS) management platform by subverting the internet’s routing system.
The attackers achieved this by hijacking Border Gateway Protocol (BGP) announcements that direct traffic to the servers hosting Virtualizor’s update files. By announcing false routes, they rerouted legitimate update requests to machines under their control, and such rerouting can be short‑lived, making it difficult for network operators to spot the anomaly in real time.
Virtualizor, a widely used control panel for provisioning and managing VPS instances, relies on automated updates to patch vulnerabilities and add features. In this incident, the malicious payload was served in place of the authentic update, giving the perpetrators the ability to execute code on any system that installed it.
Systems that accepted the tainted update could be exposed to backdoors, credential theft, or further lateral movement within hosting environments. Because VPS providers often serve dozens or hundreds of customers on a single host, a single compromised panel could cascade across many virtual machines.
The breach was first reported by security outlet BleepingComputer, which cited network logs showing abnormal route announcements coinciding with the distribution of the rogue package. Virtualizor’s developers have issued an advisory urging administrators to verify the integrity of recent updates, to revert to known‑good versions, and to compare the downloaded package’s hash against the values published on the official site while they investigate the source of the BGP hijack.
Experts note that BGP hijacking remains a low‑cost, high‑impact vector for supply‑chain attacks, especially when software distributors host update files on a limited set of IP addresses. The episode underscores the need for cryptographic signing of updates and for hosting providers to adopt route‑validation mechanisms such as RPKI to prevent unauthorized announcements. Following the incident, several internet‑exchange points have called for broader adoption of BGP security extensions to curb similar supply‑chain compromises.
Comments (0)
Be the first to comment.
Join the discussion