Latest BGP Hijack Targets Hosting Software Vendor

September 10, 2026

Latest BGP Hijack Targets Hosting Software Vendor
Image assisted/created by AI

BY Doug MadoryDirector of Internet Analysis at KentiK

This article was originally published on the Kentik Blog

Summary

This post analyzes the technical details of the BGP hijack against Softaculous Ltd, the company behind the Softaculous auto-installer and the Virtualizor VM management platform. The hijack enabled an attacker to fraudulently obtain a TLS certificate and use it to deliver a malicious Virtualizor update to a portion of the company’s customer base.


Just days ago, a BGP hijack was used as part of an attack on hosting software vendor Softaculous Ltd, the company behind the Softaculous auto-installer and the Virtualizor VM management platform. In a blog post on the incident, the company explains that an attacker used a “technically valid TLS certificate” for their domains, in concert with a BGP hijack, to deliver a “malicious Virtualizor update package” to a “small number of installations.” They advise customers to follow a sequence of steps to check if they have been impacted.

What follows is a closer look at some of the technical details of this incident.

(Free access, no subscription required)

How did the attacker hijack this IP space?

Beginning at 20:57 UTC on August 28, 2026, a new prefix entered the global routing table. 162.55.80.0/24 was announced along the AS path:

… 6204 62390 24940

This address range included IP addresses used for Softaculous’s software update endpoint as well as its client and billing site. It was a more-specific hijack of the 162.55.0.0/16 normally originated by Hetzner Online (AS24940). The route likely originated with the penultimate AS in the path, NexonHost (AS62390), either through a compromise or a customer who took advantage of gaps in their security.

The hijack also included an AS path with a forged origin. Because the attacker appended 24940 as the rightmost ASN in the path, it was considered RPKI-valid for two reasons: the ROA required the origin to be AS24940 but also because it allowed the prefix length to be anywhere between 24 and 16. As a result, this route was RPKI-valid and would not be at risk of being dropped by ASes that reject RPKI-invalid routes.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted