Threat Actors Exploit BGP Hijack to Serve Counterfeit Virtualizor Update Using Valid Softaculous TLS Certificate
A coordinated attack that combined Border Gateway Protocol (BGP) hijacking with a legitimate TLS certificate allowed cyber‑criminals to masquerade a fake Virtualizor update as an authentic Softaculous release. By rerouting internet traffic destined for Softaculous’s update servers, the perpetrators delivered malicious binaries that appeared to come from a trusted source.
In a BGP hijack, an attacker advertises false routing information, causing internet service providers to send traffic to a location under the attacker’s control. This technique, while technically sophisticated, is not new; it has been leveraged in previous supply‑chain incidents to intercept and manipulate data streams without raising immediate alarms.
Softaculous is a widely used auto‑installer for web hosting platforms, and Virtualizor is a popular virtualization management solution that often relies on Softaculous for streamlined deployments. Administrators routinely download updates from Softaculous’s domain, trusting the site’s SSL certificate to verify authenticity.
The malicious actors obtained a TLS certificate that legitimately covered Softaculous’s domains, enabling encrypted connections that passed standard browser checks. When victims’ systems requested the latest Virtualizor package, the hijacked route delivered a tampered installer signed with the valid certificate, making the counterfeit update indistinguishable from the genuine file.
Security researchers warn that such a supply‑chain compromise can grant attackers footholds on dozens or hundreds of servers, depending on the popularity of the targeted software. The malicious Virtualizor binary could install backdoors, ransomware, or other payloads, potentially exposing sensitive customer data and disrupting hosted services.
The incident, first reported by SecurityWeek, has prompted advisories from both Softaculous and network‑security firms. Recommended mitigations include enabling DNSSEC, employing certificate pinning where feasible, and monitoring BGP announcements for anomalies. Organizations are also urged to verify update integrity via checksums published on independent channels. As attackers continue to blend routing attacks with valid cryptographic credentials, the industry faces a growing need for layered verification mechanisms to protect the software supply chain.
Comments (0)
Be the first to comment.
Join the discussion