BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Summary

Hackers exploited a Border Gateway Protocol (BGP) hijack to intercept and redirect Softaculous traffic, delivering a malicious Virtualizor update. This compromised some Virtualizor installations, granting attackers persistent root access.

IFF Assessment

FOE

This incident represents a significant win for attackers, as they were able to gain persistent root access to victim systems through a sophisticated supply chain attack.

Defender Context

This incident highlights the critical importance of monitoring BGP routes for anomalies and verifying software update integrity. Defenders should implement multi-factor authentication and strict access controls for critical infrastructure management tools like Virtualizor to mitigate the impact of such supply chain attacks.

Read Full Story →