Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

URGENT: Virtualizor Compromised (31st AUG)

123457»

Comments

  • xHostsxHosts Patron Provider, Veteran

    @JohnFilch123 said:

    @xHosts said:

    @LEBUserJoe said:
    What's more concerning is I have VPS on virtualiser with few providers in this thread, to this date i've received no notification from either of them they suffered potential access.

    Beyond the hack, why aren't providers notifying customers of this?

    We sent out a email to clients about the issue a few days ago

    I think I only received an email from you and there are more providers who are using Virtualizor. Sed.

    We tried to do things in order, establish the real issue and email clients.

    The longest part was the back and forth with Virtualizor which I understand they are very busy and may take a little time to reply, once we had a clear picture we sent out the email.

    Thanked by 2JohnFilch123 forest
  • @xHosts said: We tried to do things in order, establish the real issue and email clients.

    This is great, I am pretty happy to be your client :love:

    Thanked by 3xHosts forest JohnnySac
  • SaahibSaahib Host Rep, Veteran

    Is virtualizor is not on LET, I see no statement from them here but I think a good LET base is their customer.

  • Don't Naranjatech and LiteServer also use Virtualizor?

  • @Saahib said:
    Is virtualizor is not on LET, I see no statement from them here but I think a good LET base is their customer.

    Earlier in this thread:

    @virtualizor said:
    Virtualizor — Security Incident Update

    Between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC (2026), a block of Hetzner IP addresses used by our services (162.55.80.0/24) was hit by a BGP hijack — internet traffic to those addresses was rerouted to an attacker's server (announced by AS62390 / NexonHost, via transit AS6204 / Zet.net). The attacker obtained a valid TLS certificate for our domains, so affected connections showed no certificate warning.

    Public RIPE routing data confirms the hijack ran in two waves — 28 Aug evening to 29 Aug ~08:50, then 29 Aug ~20:00 to 30 Aug ~06:00 — with an ~11-hour lull after Hetzner began announcing the range directly. Routing is now fully restored.

    Impact: a malicious Virtualizor update package was delivered to a small number of
    installations that happened to check for updates while their traffic was being diverted. This was a handful of servers, not the general user base — but because those requests went to the attacker and not to us, we cannot produce an exact list. Please treat every Virtualizor server as in scope.

    If you run Virtualizor, do this now:

    1. Check for this file: /etc/systemd/system/java-jre-update.service
      If it exists, your server was affected — do not just delete it. Contact our support if you need any help.

    2. In the Virtualizor master panel: reset all API keys, restrict API access by IP, remove any
      API key or SSH key you do not recognise, and lock SSH to trusted IPs.

    3. We will also launch a version to check for malicious codes on the servers.

    If you logged into softaculous.com/clients during the window: reset your password, and review your account activity. No cards are saved on our servers.

    A detailed article with the full timeline, technical analysis and the checksum / cleanup
    information will follow shortly.

    Thanked by 1rpqu
  • I’ve always wondered why so many providers use Virtualizor. I’m pretty sure whoever makes that decision has never actually used the user panel themselves — the UX is terrible and the whole panel feels clunky and outdated. Is it just cheap? Easy to set up?

  • Can @SolidVPS give us any info on what's going on at their side? It seems they are heavily affected.

  • JohnFilch123JohnFilch123 Member
    edited September 4

    @zephyr32 said: Can @SolidVPS give us any info on what's going on at their side?

    They already answered in a relevant thread.

    Thanked by 2forest zephyr32
  • jesus christ

  • @hostnamaste said:

    @stupidgenius said:
    From my quick research providers that have advertised or listed Virtualizor on their site over the last 6 months, pinging for viability.

    FYI
    @DediRock
    @SolidVPS
    @SmokyHosts
    @hostdare
    @xHosts
    @Fourplex
    @rarecloud
    @HostMayo
    @hostnamaste
    @LittleCreek
    @HostSlick
    @3K33

    Thanks for including @hostnamaste in the list and for checking with the providers.

    We have investigated this on our side and also confirmed with our technical team. We have checked the reported indicators and run the official Virtualizor security scan, and we have found no signs of compromise on our Virtualizor infrastructure.

    Everything is clean from our side at this time. 👍

    I know it's offtopic but what kind of bullshit advertising is this? :)

    https://i.imgur.com/miGcwCF.png

  • BlaZeBlaZe Host Rep, Veteran

    @William said:
    Yes, but its very visible and requires some ressources unlike many attacks (eg. access to BGP and an ASN, forged LOA etc.).
    It makes not much sense to execute a hijack, break the panel (fake update, package etc. - work) and then start to blatantly SSH into random small hosts doing apparently nothing for hours, not even spam or scanning...

    You got a point. Maybe the competitors did it?

  • @alincupunct said:

    I know it's offtopic but what kind of bullshit advertising is this? :)

    https://i.imgur.com/miGcwCF.png

    It's a mystery box/gotcha game, but for servers?

  • SaahibSaahib Host Rep, Veteran

    @Arirang said:
    I’ve always wondered why so many providers use Virtualizor. I’m pretty sure whoever makes that decision has never actually used the user panel themselves — the UX is terrible and the whole panel feels clunky and outdated. Is it just cheap? Easy to set up?

    Yes, its easy to setup, it works and apparently cheaper? But I think when they started, there were not many competitors. Now we have better alternatives in terms of pricing, stability, UX. Virtualizor has really lost opportunity where they could have used their existing userbase and create something even better.

  • SaahibSaahib Host Rep, Veteran

    @forest said:

    @Saahib said:
    Is virtualizor is not on LET, I see no statement from them here but I think a good LET base is their customer.

    Earlier in this thread:

    @virtualizor said:
    Virtualizor — Security Incident Update

    Between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC (2026), a block of Hetzner IP addresses used by our services (162.55.80.0/24) was hit by a BGP hijack — internet traffic to those addresses was rerouted to an attacker's server (announced by AS62390 / NexonHost, via transit AS6204 / Zet.net). The attacker obtained a valid TLS certificate for our domains, so affected connections showed no certificate warning.

    Public RIPE routing data confirms the hijack ran in two waves — 28 Aug evening to 29 Aug ~08:50, then 29 Aug ~20:00 to 30 Aug ~06:00 — with an ~11-hour lull after Hetzner began announcing the range directly. Routing is now fully restored.

    Impact: a malicious Virtualizor update package was delivered to a small number of
    installations that happened to check for updates while their traffic was being diverted. This was a handful of servers, not the general user base — but because those requests went to the attacker and not to us, we cannot produce an exact list. Please treat every Virtualizor server as in scope.

    If you run Virtualizor, do this now:

    1. Check for this file: /etc/systemd/system/java-jre-update.service
      If it exists, your server was affected — do not just delete it. Contact our support if you need any help.

    2. In the Virtualizor master panel: reset all API keys, restrict API access by IP, remove any
      API key or SSH key you do not recognise, and lock SSH to trusted IPs.

    3. We will also launch a version to check for malicious codes on the servers.

    If you logged into softaculous.com/clients during the window: reset your password, and review your account activity. No cards are saved on our servers.

    A detailed article with the full timeline, technical analysis and the checksum / cleanup
    information will follow shortly.

    Ah, I completely overlooked. If something similar happened with other provider, they would have regularly followed up, so I thought that was shared by some vzr user.

Sign In or Register to comment.