Affected Systems

Virtualizor hypervisor management software (all versions) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC. Any installation that checked for updates during this period may be compromised. Also potentially affects Webuzo, Softaculous, Backuply, SitePad, and other Softaculous products (investigation ongoing). At least 5 of 34 hypervisors confirmed compromised at one hosting provider.

Exploitation Status

Active exploitation confirmed. Attackers used BGP hijacking to intercept update traffic and delivered malicious packages that established root-level persistence via systemd service, SSH backdoor (key AAAAC3NzaC1lZDI1NTE5AAAAIP13pPAm5jmInLQYD3XNb3HwrW4cAKDcphoT4kSKrnte), unauthorized account 'proxyuser', and Java-based payload (SHA-256: b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7). Successful SSH login from 193.32.127[.]248 observed. C2 domains: cdn[.]nerat[.]cc and connect[.]ne-rat[.]xyz.

Business Impact

Hosting providers running Virtualizor face root-level compromise of hypervisors, enabling full control over host systems and all customer VMs. Attackers gained persistent access via systemd service (java-jre-update.service), SSH backdoor, and Java payload. Client-area credentials and payment data entered during the incident window may have been intercepted. No affected-version range exists; vendor cannot provide definitive list of compromised installations. Update mechanism lacked cryptographic signature verification, enabling supply chain attack. Cryptographic signing remains unimplemented as of September 2, 2026.

Urgency

🔴 Immediate

Recommended Actions

  • Run Virtualizor's official Security Analyzer (SHA-256: 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48) on every Virtualizor hypervisor immediately, regardless of version or perceived exposure
  • Check for systemd unit /etc/systemd/system/java-jre-update.service, payload /usr/lib/jvm/.cache/jre-runtime.dat, unauthorized user 'proxyuser', and SSH key AAAAC3NzaC1lZDI1NTE5AAAAIP13pPAm5jmInLQYD3XNb3HwrW4cAKDcphoT4kSKrnte in root authorized_keys
  • Rotate all Virtualizor API keys, restrict API access to trusted IP addresses only, and remove any unrecognized keys from the system
  • Block outbound connections to cdn[.]nerat[.]cc, connect[.]ne-rat[.]xyz, 31.77.220[.]138:2025, and 193.32.127[.]248 at firewall; hunt for connections to these indicators in logs from August 28-30
  • Force password reset for all client-area users who logged in or entered payment details between August 28 20:57 UTC and August 30 06:10 UTC; advise customers to review card statements and change reused passwords