{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/virtualizor/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Virtualizor"],"_cs_severities":["high"],"_cs_tags":["supply-chain-attack","bgp-hijacking","software-update-tampering"],"_cs_type":"advisory","_cs_vendors":["Softaculous"],"content_html":"\u003cp\u003eDuring a 33-hour window in late August 2026, an unidentified threat actor conducted a BGP hijack against the infrastructure belonging to Softaculous, the vendor behind the Virtualizor web hosting management platform. By hijacking IP address space associated with the vendor, the attackers intercepted legitimate traffic intended for update servers. The threat actors successfully generated a fraudulent TLS certificate to present as the legitimate vendor, allowing them to host a cloned update portal and distribute malicious updates directly to Virtualizor users. The incident demonstrates a sophisticated supply-chain attack vector that bypasses traditional endpoint and network perimeter defenses by compromising the underlying internet routing fabric. The vendor has reported that the total impact remains unknown due to the lack of visibility into the traffic diverted through the attacker's infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe threat actor performs reconnaissance on Softaculous/Virtualizor infrastructure to identify BGP prefixes and update server endpoints.\u003c/li\u003e\n\u003cli\u003eThe actor initiates a BGP hijack (T1498.001) to commandeer the victim's IP space, redirecting traffic through attacker-controlled infrastructure.\u003c/li\u003e\n\u003cli\u003eThe actor requests and obtains a fraudulent TLS certificate (T1588.003) for the domain names associated with Virtualizor update services.\u003c/li\u003e\n\u003cli\u003eA cloned update server is deployed on the hijacked IP range, mirroring the vendor's update portal.\u003c/li\u003e\n\u003cli\u003eVirtualizor systems checking for updates are transparently redirected to the malicious portal due to the BGP route manipulation.\u003c/li\u003e\n\u003cli\u003eVictim systems download and execute the malicious update package (T1195.002) delivered via the attacker's server.\u003c/li\u003e\n\u003cli\u003eThe compromised hosts initiate outbound connections to attacker-controlled C2 infrastructure (T1071.001).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign compromised the update mechanism of the Virtualizor platform, a critical tool for web hosting management. The impact includes the potential for widespread remote code execution across thousands of hosted web environments. Because the traffic was intercepted at the network layer, the vendor lacked logs to identify the number of victims or the specific nature of the malicious payloads delivered.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit BGP routing logs (e.g., from BGPStream or internal routers) for unauthorized advertisements or path changes involving Softaculous IP prefixes during the period of August 2026.\u003c/li\u003e\n\u003cli\u003eReview system logs on Virtualizor nodes for update activities occurring between the affected Friday and Sunday window to identify potential unauthorized binaries.\u003c/li\u003e\n\u003cli\u003eImplement RPKI (Resource Public Key Infrastructure) validation on network infrastructure to prevent unauthorized BGP origin advertisements.\u003c/li\u003e\n\u003cli\u003eVerify the certificate authority (CA) and serial number for TLS certificates associated with critical update endpoints to ensure they match expected, vendor-provided fingerprints.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T06:00:49Z","date_published":"2026-09-03T06:00:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bgp-hijack-virtualizor/","summary":"An unidentified threat actor leveraged a 33-hour BGP hijack to intercept traffic and serve malicious updates for the Virtualizor web hosting platform via a spoofed update portal.","title":"BGP Hijacking Campaign Targeting Virtualizor Software Updates","url":"https://feed.craftedsignal.io/briefs/2026-09-bgp-hijack-virtualizor/"}],"language":"en","title":"CraftedSignal Threat Feed - Virtualizor","version":"https://jsonfeed.org/version/1.1"}