BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Overview
Hackers have executed a Border Gateway Protocol (BGP) hijack to redirect traffic meant for Softaculous, allowing them to deliver a malicious update for Virtualizor. This incident has compromised at least five out of thirty-four Virtualizor hypervisors at a hosting provider, granting the attackers root access to these systems. The attack window is reported to have occurred on August 28. This breach raises concerns for users relying on Virtualizor for virtualization management, as the malicious update could lead to unauthorized control over their servers. Organizations using this software should take immediate steps to assess their systems for vulnerabilities and potential intrusions.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Virtualizor hypervisors, Softaculous traffic
- Action Required: Users should assess their Virtualizor installations for unauthorized changes and apply any available security updates.
- Timeline: Ongoing since August 28, 2023
Original Article Summary
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57
Impact
Virtualizor hypervisors, Softaculous traffic
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since August 28, 2023
Remediation
Users should assess their Virtualizor installations for unauthorized changes and apply any available security updates. Regular monitoring of system logs and network traffic is also recommended.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Update, Malware.