Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.

Virtualizor is a legacy web control panel from Softaculous that hosting providers use to create, sell, and manage virtual private servers (VPS).

An urgent notice from the vendor warns that between 20:57 UTC on August 28 and 06:10 UTC on August 30, an attacker rerouted a block of Hetzner-hosted IP addresses in a BGP (Border Gateway Protocol) hijacking attack.

This enabled the threat actor to divert traffic from Softaculous software update systems and the client/billing portal.

BGP hijacking occurs when a network operator falsely announces a route to IP addresses belonging to another organization. Other organizations may accept the fraudulent route as the preferred one.