Hackers Push Malicious Virtualizor Update in BGP Hijacking Attack
Cybercriminals hijacked BGP routing for Virtualizor VPS management software to redirect update requests and push malicious code.

In a sophisticated supply chain attack, malicious actors have compromised the update infrastructure of the Virtualizor VPS management software by hijacking its BGP routing. According to BleepingComputer, the attackers successfully redirected update traffic to rogue servers.
This malicious redirection allowed the operators behind the attack to distribute harmful payloads disguised as legitimate software updates to unsuspecting users. Such tactics highlight the vulnerability of core internet routing protocols when leveraged by advanced cybercriminals.
BGP hijacking attacks are particularly dangerous because they occur at the network infrastructure level, making it difficult for end-users and administrators to detect that their trusted update channels have been subverted. Hosting providers relying on Virtualizor faced significant risks as their automated or manual update routines fetched compromised files.
For IT professionals and cloud service providers globally and in the broader region, this incident underscores the critical importance of robust network security and supply chain vigilance. Ensuring that routing infrastructures are protected against BGP manipulation is more crucial than ever.
Security experts are currently urging affected system administrators to audit their environments for indicators of compromise and apply necessary patches. Implementing technologies like Resource Public Key Infrastructure (RPKI) is increasingly viewed as an essential defense against similar network-level hijacking threats.



