Attackers allegedly hijacked BGP routes for Hetzner’s 162.55.80.0/24 between 28 and 30 August, diverting traffic destined for Softaculous and Virtualizor infrastructure to malicious update servers. The interception reportedly used valid Let’s Encrypt certificates to avoid TLS warnings and delivered a trojanized package masquerading as Virtualizor version 3.2.9.8; Virtualizor clients reportedly did not cryptographically verify update packages.
The malicious update injected PHP @exec() calls into core files that ran as root through Virtualizor’s virt_check.php scheduled task, allegedly installing the widdow.jar Java RAT associated with the nerat MaaS platform along with systemd, SSH-key, and local-user persistence. Although routing has been restored, operators should treat Virtualizor hypervisors and hosted guest disks as potentially compromised, isolate and preserve affected systems, investigate suspicious systemd services, rotate infrastructure credentials, and rebuild confirmed compromised hosts from bare metal.

Trace attribution and downstream blast radius.
13 events from the most recent confirmed update back to the earliest known activity.
Softaculous released Virtualizor version 3.2.9.9, adding a Security Analyzer tool to the administrative panel to help operators assess systems following the malicious-update incident.
BGPHorizon reported that the alleged 162.55.80.0/24 hijack retained Hetzner's AS24940 as its BGP origin through a path ending in "6204 62390 24940." Because Hetzner's ROA authorized AS24940 for prefixes through /24, the route reportedly passed RPKI origin validation and did not create a conventional MOAS conflict.
The reported malicious update installed the widdow.jar Java RAT, associated with the Nerat malware-as-a-service platform, and created the root-level java-jre-update.service systemd persistence service. It also reportedly added a root SSH key and created a local proxyuser account for interactive access.
A report alleged that Virtualizor's update distribution mechanism delivered a package displayed as version 3.2.9.8 while the backend remained at 3.2.9.7. The package reportedly inserted PHP execution calls into core files that ran as root through Virtualizor's virt_check.php cron job.
The BGP hijack ceased after two flapping diversion waves totaling roughly 22 hours, and no further diversion was reported after 06:10 UTC. The campaign involved approximately 10,600 route withdrawals and at peak influenced best-route selection for about 72% of observed collector peers.
The vendor independently confirmed interception after a host on the diverted route served a fraudulent certificate for Softaculous domains.
Attackers began announcing Hetzner's more-specific 162.55.80.0/24 prefix through AS62390 (NexonHost) and AS6204 (Zet.net), diverting traffic intended for Softaculous infrastructure. The diversion enabled interception of Virtualizor and Softaculous-related traffic.
During the BGP diversion, attackers obtained valid Let's Encrypt certificates for virtualizor.com, api.virtualizor.com, and files.virtualizor.com, avoiding TLS warnings. They used the interception to provide malicious Virtualizor updates to a limited number of hypervisor servers; Virtualizor clients did not cryptographically verify update packages.
Virtualizor published a security scan script to help operators conduct additional checks following the malicious-update incident. It also advised preserving evidence and contacting support if the java-jre-update.service indicator is found.
Softaculous stated that its investigation had found no evidence that malicious updates were distributed for products other than Virtualizor. The company said its investigation remained ongoing.
Softaculous said it is implementing a code-signing mechanism for all software packages following the incident, after Virtualizor update clients were found not to cryptographically verify package integrity.
Softaculous advised client-area users active during the incident to reset passwords, review payment-card activity where applicable, and rotate reused credentials. It also said it was invalidating client-area sessions created during the incident window and instructed all Virtualizor operators to investigate for compromise indicators, including the suspicious java-jre-update.service unit.
AlbaHost reported that 5 of 34 examined Virtualizor hypervisor nodes had root-level compromise from the malicious update. It observed modified core files, a root SSH key, Java-based persistence, and an unauthorized proxyuser account, including a successful SSH login from 193.32.127[.]248.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
19 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcexakep.ru
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesoftaculous.com
Open sourcelowendtalk.com
Open sourcevirtualizor.com
Open sourcemetr.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.