Softaculous reported a BGP hijack of part of its IP address space: a network announced address space it did not control and diverted the traffic. During the incident, a small number of Virtualizor installations received a malicious update.

According to the company, the hijack lasted from about 20:57 UTC on 28 August to about 06:10 UTC on 30 August. The attacker obtained a valid TLS certificate for Softaculous domains, so affected connections showed no certificate warning.

Softaculous recommends checking Virtualizor servers for /etc/systemd/system/java-jre-update.service. If the file is present, the server was affected.

The company also advises resetting all Virtualizor API keys, restricting API access to trusted IP addresses, and checking the server for unknown SSH keys, accounts, cron jobs, and outbound connections.

Claim check:

  • During the BGP hijack, an unauthorized announcement of part of Softaculous’s IP address space diverted traffic to an attacker’s server. (confirmed by the publication itself: evidence; «Between 28 August 2026 at approximately 20:57 UTC and 30 August 2026 at approximately 06:10 UTC, a block of IP addresses used by Softaculous services (162.55.80.0/24, part of our infrastructure at Hetzner) was affected by a BGP hijack: an unauthorized announcement of that address space by an unrelated network, which diverted internet traffic destined for those addresses to a server operated by an attacker.»)
  • Softaculous confirmed that a malicious Virtualizor update reached a small number of installations that checked for updates while their traffic was diverted. (confirmed by the publication itself: evidence; «We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted.»)
  • According to Softaculous, the hijack lasted from about 20:57 UTC on 28 August to about 06:10 UTC on 30 August. (confirmed by the publication itself: evidence; «Incident window 28 Aug 20:57 UTC -> 30 Aug ~06:10 UTC (~33.3 hours)»)
  • The attacker obtained a valid TLS certificate for Softaculous domains, so affected connections showed no certificate warning. (confirmed by the publication itself: evidence; «The attacker obtained a technically valid TLS certificate for our domains, so connections affected by the hijack showed no certificate warning.»)
  • Softaculous recommends checking Virtualizor servers for /etc/systemd/system/java-jre-update.service; if the file is present, the server was affected. (confirmed by the publication itself: evidence; «Check for the indicator of compromise. Look for /etc/systemd/system/java-jre-update.service. If it is present, your server was affected — do not simply delete it; contact us.»)
  • The company also recommends resetting all Virtualizor API keys, restricting API access to trusted IP addresses, and checking the server for unknown SSH keys, accounts, cron jobs, and outbound connections. (confirmed by the publication itself: evidence; «In the Virtualizor master (admin) panel, reset all API keys, restrict API access to trusted IP addresses, and remove any API key you do not recognize. Audit access. Review the server for unknown SSH keys, new user accounts, unexpected scheduled tasks or cron jobs, and unexpected outbound connections.»)

Publications:

Primary sources:

score 79.5 out of 100 · kind: incident