Attackers Hijacked Softaculous Network to Spread Malware

The 33-hour breach exploited BGP routing and missing code-signing protocols, compromising software updates.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration of a steel server rack facade with complex fiber optic cabling, representing network infrastructure security.
Attackers hijacked the Softaculous network for 33 hours in September 2026, distributing malware through unverified software updates due to BGP and code-signing vulnerabilities. AI Illustration. Upload story photo >

Live Poll

Do you trust that your software providers are adequately securing your data against infrastructure attacks?

Attackers hijacked the Softaculous IP address block 162.55.80.0/24 in September 2026 to distribute malicious files through compromised Virtualizor updates. The incident remained undetected for 22 hours, ultimately spanning a total of 33 hours.

Why it matters

The breach highlights systemic risks in software distribution chains caused by the absence of cryptographically verified updates and vulnerabilities in global routing security. These lapses allowed malicious traffic to masquerade as legitimate software transmissions.

The attackers exploited BGP routing security weaknesses and the TLS certificate acquisition process by crafting RPKI-valid announcements with forged origin AS paths. The hijacked 162.55.80.0/24 block remained under unauthorized control for 12 hours during the first episode and 10 hours during the second.

The players

Softaculous

A UAE-based software company specializing in automated web application installers.

Hetzner Online

A German data center operator and hosting provider where the targeted address space was hosted.

Zet.net

An internet service provider involved in the routing path that failed to detect the hijacking for 22 hours.

The details

The attackers utilized forged BGP (Border Gateway Protocol, the standard for routing internet traffic) origin AS paths, which were accepted by transit provider Zet.net because the hosting environment failed to implement strict validation. Because Softaculous did not employ code signing—a digital signature process that validates the authenticity and integrity of software—the poisoned Virtualizor updates were distributed to users without triggering security warnings.

Timeline

  1. September 2026: Attackers successfully hijacked the Softaculous network infrastructure.

The Tech Race

This event underscores the persistent challenge of securing the internet's routing infrastructure against sophisticated BGP hijacking tactics. It demonstrates that even when RPKI-valid certificates are used, flaws in how providers validate origin AS paths allow attackers to circumvent standard security measures.

Users of the Virtualizor platform who downloaded updates during the 33-hour window in September 2026 may be at risk. Organizations should verify the integrity of their software installs and review logs for unauthorized traffic originating from their management networks.

The takeaway

The lack of cryptographically verified updates remains a critical vulnerability that renders users susceptible even when network routing is hijacked. Administrators should prioritize the implementation of code signing as a fundamental requirement for all automated software delivery pipelines.

Further reading

For more on evolving threat vectors and network security, visit Cybersecurity.

Source note: This article includes information reported by RocketNews.

Live Poll

Do you trust that your software providers are adequately securing your data against infrastructure attacks?

Attackers Hijacked Softaculous Network to Spread Malware