Hackers Hijack BGP Routing to Infect Virtualizor VPS Management Software
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON — Hackers successfully delivered malicious software updates to users of Virtualizor, a popular virtual private server management platform, after hijacking Border Gateway Protocol (BGP) routing for the company's update infrastructure. The attack, confirmed on Sept. 1, 2026, represents a significant escalation in supply chain compromises by exploiting fundamental internet routing mechanisms to intercept legitimate software distribution.
The intrusion allowed attackers to redirect traffic intended for Virtualizor's official update servers to malicious endpoints controlled by the threat actors. Users who accepted automatic updates during the window of the hijacking received compromised versions of the management software. Once installed, the malicious code likely granted unauthorized access to the VPS environments managed through the platform, potentially exposing sensitive data and allowing further lateral movement within victim networks.
Virtualizor is widely used by hosting providers and system administrators to manage virtualization resources. The compromise of its update channel created a single point of failure that affected a broad range of downstream users globally. Security experts noted that BGP hijacking remains a potent vector for large-scale attacks because it operates at the network layer, making it difficult for end-users to distinguish between legitimate and fraudulent traffic without specialized monitoring tools.
The motive behind the attack remains unknown. No ransom demands have been publicly linked to the incident, nor have any specific threat actors claimed responsibility. The timing of the breach, occurring in the early afternoon on Sept. 1, suggests a coordinated effort to maximize impact during active business hours across multiple time zones.
Virtualizor has since worked to restore legitimate routing paths and issued emergency patches to clean infected systems. Administrators are urged to manually verify the integrity of their installations and disable automatic updates until further notice. The incident highlights the fragility of internet infrastructure and the risks associated with relying on BGP for critical software distribution without additional cryptographic verification at the application level.
Questions remain regarding the full scope of the compromise. It is unclear how many organizations were affected or whether the attackers established persistent backdoors that could survive system reboots or patching efforts. Investigators are working to determine if the stolen credentials or access vectors have been used for further unauthorized activities. As of now, no data exfiltration has been confirmed, though the potential for long-term espionage or financial theft remains a primary concern for affected hosting providers.