Ethical Hacking News
A recent incident of cyber attack has been reported, where hackers exploited a vulnerability in the Virtualizor update process to deliver a malicious package to some installations. The attack, which was carried out using a Border Gateway Protocol (BGP) hijack, resulted in the establishment of persistent root access on several servers. The affected Virtualizor installations were affected by a malicious update package that installed Java 17 and executed a systemd service to establish persistence. The attackers also used the diverted update traffic to steal sensitive information from client-area sessions and payment-entry traffic during the incident window. The Virtualizor company has since released Patch 9 with a Security Analyzer to mitigate the issue.
The Virtualizor update process was exploited by hackers, allowing them to deliver a malicious package to some installations. The attack resulted in the establishment of persistent root access on several servers using a BGP hijack. The hackers stole sensitive information from client-area sessions and payment-entry traffic during the incident window. The company has released Patch 9 with a Security Analyzer to address the vulnerability. Operators are advised to keep software up to date, check for known artifacts of compromise, and implement robust security measures. The attack highlights the importance of protecting against supply chain attacks and taking proactive measures to prevent similar attacks.
A recent incident of cyber attack has been reported, where hackers exploited a vulnerability in the Virtualizor update process to deliver a malicious package to some installations. The attack, which was carried out using a Border Gateway Protocol (BGP) hijack, resulted in the establishment of persistent root access on several servers.
The attack, which is believed to have occurred between August 28 and August 30, 2026, involved the hackers using a BGP hijack to divert traffic to an attacker-operated server. The server was used to deliver a modified Virtualizor package to the affected installations, which included a malicious payload that installed Java 17 and executed a systemd service to establish persistence.
The malicious payload also created an unauthorized account named "proxyuser" and established an SSH connection to that account from the IP address 193.32.127[.]248. The attackers also used the diverted update traffic to steal sensitive information from client-area sessions and payment-entry traffic during the incident window.
The Virtualizor company has since released Patch 9 with a Security Analyzer, which has been added to release-candidate and stable branches. However, the company has stated that cryptographic package signing remains a future work, and operators are advised to run the official scanner to check for known artifacts of compromise.
The incident has highlighted the importance of keeping software up to date and being cautious when installing updates. The Virtualizor company has also emphasized the need for operators to check their servers regularly for signs of compromise and to rotate and restrict API credentials.
The attack is also a reminder of the need for robust security measures in place to protect against supply chain attacks. The use of BGP hijack to deliver a malicious update package is a classic example of a supply chain attack, where the attacker manipulates the update process to deliver malicious code.
In conclusion, the recent Virtualizor update attack highlights the importance of staying vigilant and taking proactive measures to protect against cyber attacks. Operators are advised to take immediate action to patch their systems and to implement robust security measures to prevent similar attacks in the future.
Related Information:
https://www.ethicalhackingnews.com/articles/BPG-Hijack-Delivers-Malicious-Virtualizor-Update-Establishing-Persistent-Root-Access-ehn.shtml
https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html
Published: Wed Sep 2 11:32:14 2026 by llama3.2 3B Q4_K_M