Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

URGENT: Virtualizor Compromised (31st AUG)

1235

Comments

  • aphexaphex Member

    @vicaya said: It's bewildering that a public facing endpoint doesn't have CAA or use DNS-01 resolvers. OTOH, why not use Cloudflare edge IPs for software distribution, which is practically impossible to hijack, besides egress cost savings and DDoS protection?

    It's software written like PHP 4, they don't understand digital signatures, everything is on a single hetzner machine, and the target for most of its customers is people that don't know how to install wordpress on cpanel

    Thanked by 2forest tentor
  • AlbaHostAlbaHost Member, Patron Provider

    @aphex said:

    @vicaya said: It's bewildering that a public facing endpoint doesn't have CAA or use DNS-01 resolvers. OTOH, why not use Cloudflare edge IPs for software distribution, which is practically impossible to hijack, besides egress cost savings and DDoS protection?

    It's software written like PHP 4, they don't understand digital signatures, everything is on a single hetzner machine, and the target for most of its customers is people that don't know how to install wordpress on cpanel

    The criticism about signed updates and infrastructure design is fair. The rest is just pointless elitism. Using a control panel doesn’t mean someone can’t administer a server; it means they prefer automation over doing repetitive work manually. Also, if we’re going to criticise Virtualizor for things like CAA, it’s worth noting that other panels don’t necessarily have CAA configured either. Judge the actual security architecture, not the customers using the product.

    Thanked by 1forest
  • @AlbaHost said: cdn.nerat.cc

    "nerat" could mean 'Not rat" from russian slang "не рат", also qwins is hosting who being widely advertised on russian "hacking forums" (like lolzteam which is operated on russian government hostings)
    so attackers could be russian slaves

    @Obelous said: connect.ne-rat.xyz

    this domain proves theory too

    Thanked by 2oloke AlbaHost
  • @AndreyGubanov said:

    @AlbaHost said: cdn.nerat.cc

    "nerat" could mean 'Not rat" from russian slang "не рат", also qwins is hosting who being widely advertised on russian "hacking forums" (like lolzteam which is operated on russian government hostings)
    so attackers could be russian slaves

    @Obelous said: connect.ne-rat.xyz

    this domain proves theory too

    And well, also the fact that their dashboard (web.ne-rat.xyz) was in Russian.

    Thanked by 1AndreyGubanov
  • AlbaHostAlbaHost Member, Patron Provider
    edited August 31

    @AndreyGubanov said:

    @AlbaHost said: cdn.nerat.cc

    "nerat" could mean 'Not rat" from russian slang "не рат", also qwins is hosting who being widely advertised on russian "hacking forums" (like lolzteam which is operated on russian government hostings)
    so attackers could be russian slaves

    @Obelous said: connect.ne-rat.xyz

    this domain proves theory too

    The thing is that qwins ltd is reselling before it was from dataforest (which dataforest was fast to kick them out), and now the domain mentioned and the IP is from femo it solution limited and the upstream is aurologic GmbH!

  • @AlbaHost said:

    @AndreyGubanov said:

    @AlbaHost said: cdn.nerat.cc

    "nerat" could mean 'Not rat" from russian slang "не рат", also qwins is hosting who being widely advertised on russian "hacking forums" (like lolzteam which is operated on russian government hostings)
    so attackers could be russian slaves

    @Obelous said: connect.ne-rat.xyz

    this domain proves theory too

    The thing is that qwins ltd is reselling before it was from dataforest, and now the domain mentioned and the IP is from femo it solution limited and the upstream is aurologic GmbH!

    aurologic and dataforest is most used dedi providers russians use to resell vps
    i saw decent amount russian hosts who selling 2 bucks vps for their local community and 90% of them has upstream aurologic or dataforest (mostly dataforest)
    cuz they cant go to europe to setup colo for obvious reasons, so since aurologic and dataforest support byoip (for like 20 eur setup fee) and has cool prices even today thats almost the only way to start hosting

    (and i think you guys know that aurologic dont really care who their customers are, they still provide services to aeza LOL after a 1.5 since aeza ceo was arrest and since year US sanctioned them)

    Thanked by 2AlbaHost oloke
  • HOSTCAYHOSTCAY Member, Host Rep
    edited August 31

    @MannDude said:

    @backtogeek said:

    @MannDude said:

    @backtogeek said:
    Even more crazy when you consider VirtFusion offer migration services.

    Since when?

    They always have.

    They haven't. Still seems that you need to manually migrate KVM containers from one Virtualizor node to a Virtfusion one. Their docs ( https://docs.virtfusion.com/ ) doesn't even mention the word "virtualizor" anywhere.

    Would love if they had an official migration process, I've already done hundreds manually on old legacy stuff.

    Don’t want to sound stupid, but I migrated around 1,300 VMs from Virtualizor to VF using OpenClaw + Opus. I did it gradually in batches of around 20, and the whole process took about a week back in July, with only a couple of hours of downtime while rerouting everything.

    After their last security compromise, I’d had enough and haven’t looked back since. It’s probably the worst and buggiest panel I’ve ever used. I can’t believe I stuck with it for so long, especially now that I can fit around 30–40% more VMs on the exact same hardware with VF. Makes me think something with Virtualizor’s memory ballooning or resource management wasn’t working properly.

  • Its a scary feeling, that something will happen again.

  • xHostsxHosts Patron Provider, Veteran

    A update of 3.2.9 is currently showing but nothing on their change log at this time ….

  • AndreixAndreix Host Rep, Veteran

    @xHosts said:
    A update of 3.2.9 is currently showing but nothing on their change log at this time ….

    I'd wait a little before clicking the "Update now" button...

  • @Andreix said:

    @xHosts said:
    A update of 3.2.9 is currently showing but nothing on their change log at this time ….

    I'd wait a little before clicking the "Update now" button...

    Press it! No risk, no fun 🤣

    Also, it could be worse. You could let me in your house and the result would be that all your cheese is gone. Certainly way worse than this.

  • jsgjsg Member, Resident Benchmarker

    @AlbaHost said:

    @vicaya said:
    It's bewildering that a public facing endpoint doesn't have CAA or use DNS-01 resolvers. OTOH, why not use Cloudflare edge IPs for software distribution, which is practically impossible to hijack, besides egress cost savings and DDoS protection?

    They added CAA now, and pushed the update. And that's after all this shit happened not before!

    So while @virtualizor seems to have "ignored" my comment, they actually seem to have got the message ...

    THAT alone (not having a CAA record) IMO clearly showed that they either are clueless or utterly careless re their customers, or both.

  • jsgjsg Member, Resident Benchmarker

    @Obelous said:

    @AndreyGubanov said:

    @AlbaHost said: cdn.nerat.cc

    "nerat" could mean 'Not rat" from russian slang "не рат", also qwins is hosting who being widely advertised on russian "hacking forums" (like lolzteam which is operated on russian government hostings)
    so attackers could be russian slaves

    @Obelous said: connect.ne-rat.xyz

    this domain proves theory too

    And well, also the fact that their dashboard (web.ne-rat.xyz) was in Russian.

    Or it confirms that someone wanted the attack to look "russian" ...

    The (sad) fact is that attribution usually is really hard.

  • Looks like at least 270 Virtualizor hosts were compromised, from what I can see on Censys

  • torchbytetorchbyte Member, Patron Provider
    edited August 31

    Looks like Virtualizor pushed an update to try and get rid of the malware:

    /var/virtualizor/security_analyzer/iocs.json
    
    {
        "schema": 1,
        "updated": "2026-08-31",
        "note": "Signatures for the 2026-08-29 BGP hijack \/ 'nerat-widdow' campaign, confirmed against the raw community response script (files.xhosts.uk\/contain-node.sh), not just a summary of it. Values not independently reproduced from a live compromised host by us - treat file_hashes\/ssh_keys entries as high-confidence but not first-party confirmed until cross-checked against your own IR findings.",
        "systemd_units": [
            {
                "id": "known_ioc_java_jre_update",
                "severity": "critical",
                "unit_name": "java-jre-update.service",
                "auto_remediate": true,
                "description": "Rogue persistence unit installed by the nerat\/widdow campaign delivered via the Aug 29 2026 BGP hijack of files.virtualizor.com."
            }
        ],
        "file_hashes": [
            {
                "id": "known_ioc_nerat_payload",
                "severity": "critical",
                "path": "\/usr\/lib\/jvm\/.cache\/jre-runtime.dat",
                "sha256": "b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7",
                "auto_remediate": true,
                "description": "RAT payload referenced by java-jre-update.service's WorkingDirectory."
            }
        ],
        "marker_files": [
            {
                "id": "known_ioc_nerat_marker",
                "severity": "high",
                "path": "\/usr\/lib\/jvm\/.cache\/.installed",
                "auto_remediate": true,
                "description": "Installer marker left by the nerat\/widdow campaign."
            },
            {
                "id": "known_ioc_widdow_jar_staging",
                "severity": "high",
                "path": "\/tmp\/widdow.jar",
                "auto_remediate": true,
                "description": "Second-stage payload jar staged by the nerat\/widdow campaign's exec chain (wget -> java -jar -> rm -f). Normally self-deleted after it runs, so a lingering copy usually means execution was interrupted - still worth quarantining and investigating why it didn't clean itself up."
            }
        ],
        "ssh_keys": [
            {
                "id": "known_ioc_nerat_ssh_key",
                "severity": "critical",
                "key_body": "AAAAC3NzaC1lZDI1NTE5AAAAIP13pPAm5jmInLQYD3XNb3HwrW4cAKDcphoT4kSKrnte",
                "auto_remediate": true,
                "description": "Attacker-added SSH public key, searched for in root\/home authorized_keys files."
            }
        ],
        "core_files_watched": [
            "globals.php",
            "_universal.php",
            "zzvirtservice"
        ],
        "core_file_injected_strings": [
            "cdn.nerat.cc\/installer\/widdow.jar",
            "connect.ne-rat.xyz",
            "jre-runtime.dat"
        ],
        "known_c2_domains": [
            {
                "id": "known_ioc_nerat_c2_domain_cdn",
                "severity": "critical",
                "domain": "cdn.nerat.cc",
                "description": "nerat\/widdow campaign C2\/staging domain - sinkholed via \/etc\/hosts regardless of what else is found, since no node has a legitimate reason to resolve it."
            },
            {
                "id": "known_ioc_nerat_c2_domain_connect",
                "severity": "critical",
                "domain": "connect.ne-rat.xyz",
                "description": "nerat\/widdow campaign C2\/staging domain - sinkholed via \/etc\/hosts regardless of what else is found, since no node has a legitimate reason to resolve it."
            }
        ],
        "process_patterns": [
            {
                "id": "known_ioc_nerat_process",
                "severity": "critical",
                "pattern": "\\b(jre-runtime\\.dat|widdow|connect\\.ne-rat\\.xyz|nerat)\\b",
                "description": "nerat\/widdow RAT process patterns. Word-boundary anchored - an unanchored 'nerat' matched the plain English word 'generate' as a substring, which would have pkill -f'd any legitimate process with 'generate' anywhere on its command line."
            }
        ],
        "history_markers": [
            "MASSDONE44",
            "2ip\\.io.*masterkey"
        ],
        "self_whitelist_ip_watch": [
            "193.32.127.248"
        ]
    }
    
    Thanked by 1oloke
  • vovlervovler Member

    inb4 "Mythos 6 breaks sandbox and hacks Virtualizor" articles :D

  • @xHosts said:
    A update of 3.2.9 is currently showing but nothing on their change log at this time ….

    Why not migrate to VirtFusion? Most customers would be understanding even if it causes some downtime, as it would spare them the mental burden of constantly wondering when the next drama will unfold.

    Thanked by 2forest tentor
  • Why not migrate to VirtFusion? Most customers would be understanding even if it causes some downtime, as it would spare them the mental burden of constantly wondering when the next drama will unfold.

    Does VirtFusion support LVM Thin storage?

  • Omg. What the fccc :'(

  • MikeAMikeA Patron Provider, Veteran
    edited August 31

    @juniorrrrr said:

    Why not migrate to VirtFusion? Most customers would be understanding even if it causes some downtime, as it would spare them the mental burden of constantly wondering when the next drama will unfold.

    Does VirtFusion support LVM Thin storage?

    edit: oops I don't think lvm, but yes thin. however, very easy to migrate.

  • @MikeA said:

    @juniorrrrr said:

    Why not migrate to VirtFusion? Most customers would be understanding even if it causes some downtime, as it would spare them the mental burden of constantly wondering when the next drama will unfold.

    Does VirtFusion support LVM Thin storage?

    edit: oops I don't think lvm, but yes thin. however, very easy to migrate.

    Yeah, thin provisioning itself isn't really the issue. My concern is the extra filesystem/qcow2 COW layer.

    We're currently using LVM Thin with block devices for our KVM nodes. From what I understand VirtFusion's default local storage is file-backed qcow2 on ext4.

    With qcow2, small random writes can result in additional allocation and metadata I/O due to the qcow2 cluster/COW layer on top of the host filesystem. I remember this being discussed quite a bit in the Proxmox community as write amplification.

    That's one of the reasons I'd prefer to keep LVM Thin rather than move all of our VPS storage to qcow2 files.

  • forestforest Member
    edited August 31

    @juniorrrrr said: With qcow2, small random writes can result in additional allocation and metadata I/O due to the qcow2 cluster/COW layer on top of the host filesystem. I remember this being discussed quite a bit in the Proxmox community as write amplification.

    The qcow2 images can be generated with preallocation=full and nocow=on.

    I agree that putting each VM image on LVM is better than a bunch of qcow2 files on a filesystem though, but for other reasons (it's a lot easier to corrupt a filesystem, even one like ZFS, than it is to corrupt LVM metadata).

    Thanked by 2MikeA JohnnySac
  • Yes, they got what they deserved because they often 'hack' their own users.

  • wait how about softaculous?

  • Providers still using Virtualizor really need to ditch it and switch to VirtFusion already.

    Thanked by 2forest Gravely
  • @hezekiahshare said:
    wait how about softaculous?

    virtualizor, softaculous, and webuzo got all ssl cert compromised so it's fun to triple check all of them!

    @nunim said:
    Softaculous also got new SSL certs at the exact same time as this happened. All of these products received new SAN certs around the same time that don't match the previous issuance patterns:

    https://www.certkit.io/tools/ct-logs/?query=softaculous.com
    https://www.certkit.io/tools/ct-logs/?query=webuzo.com
    https://www.certkit.io/tools/ct-logs/?query=virtualizor.com

    So my worry is that other services were impacted.

  • hostnamastehostnamaste Member, Patron Provider

    @stupidgenius said:
    From my quick research providers that have advertised or listed Virtualizor on their site over the last 6 months, pinging for viability.

    FYI
    @DediRock
    @SolidVPS
    @SmokyHosts
    @hostdare
    @xHosts
    @Fourplex
    @rarecloud
    @HostMayo
    @hostnamaste
    @LittleCreek
    @HostSlick
    @3K33

    Thanks for including @hostnamaste in the list and for checking with the providers.

    We have investigated this on our side and also confirmed with our technical team. We have checked the reported indicators and run the official Virtualizor security scan, and we have found no signs of compromise on our Virtualizor infrastructure.

    Everything is clean from our side at this time. 👍

    Thanked by 2stupidgenius s0n1c
  • s0n1cs0n1c Member

    @hostnamaste said:

    @stupidgenius said:
    From my quick research providers that have advertised or listed Virtualizor on their site over the last 6 months, pinging for viability.

    FYI
    @DediRock
    @SolidVPS
    @SmokyHosts
    @hostdare
    @xHosts
    @Fourplex
    @rarecloud
    @HostMayo
    @hostnamaste
    @LittleCreek
    @HostSlick
    @3K33

    Thanks for including @hostnamaste in the list and for checking with the providers.

    We have investigated this on our side and also confirmed with our technical team. We have checked the reported indicators and run the official Virtualizor security scan, and we have found no signs of compromise on our Virtualizor infrastructure.

    Everything is clean from our side at this time. 👍

    maybe this is a sign, and gods giving you one more chance to switch to Virtfusion. The next time Virtualizor gets hacked, u may not be so lucky 😂

Sign In or Register to comment.