Attackers Hijacked Softaculous to Distribute Malware

Cybercriminals manipulated internet routing to poison software updates over a 33-hour period.

Updated on Sept. 24, 2026 in Cybersecurity

Attackers Hijacked Softaculous to Distribute Malware

Live Poll

Do you trust that your software providers are adequately securing your data against infrastructure attacks?

Attackers hijacked Softaculous network infrastructure by seizing an IP address block to distribute malicious software. The incident involved two separate hijacking episodes that went undetected for 22 hours.

Why it matters

The breach occurred because Softaculous failed to use cryptographically verified updates, allowing attackers to intercept and compromise files. Vulnerabilities in BGP routing security and ineffective validation at transit providers enabled the exploit.

The attackers seized the 162.55.80.0/24 IP address block using RPKI-valid announcements with forged origin AS paths. The intrusion leveraged weaknesses in TLS certificate acquisition and BGP routing protocols.

The players

Softaculous

A UAE-based company providing software auto-installers that failed to implement code signing for updates.

Hetzner Online

A web hosting provider that hosted the compromised IP space and responded to the routing hijacking.

Zet.net

A network transit provider that, alongside Softaculous, failed to detect the unauthorized routing for 22 hours.

The details

The attackers intercepted and poisoned Virtualizor software updates while bypassing standard security checks. Hosting provider Hetzner Online required 12 hours to address the first hijacking and nearly 10 hours for the second attempt.

Timeline

  1. September 2026: Attackers hijacked Softaculous network infrastructure.

The Tech Race

This incident highlights how legacy weaknesses in global routing protocols continue to outpace modern authentication efforts. It exposes the structural vulnerability of relying on RPKI validation when origin paths can be forged by sophisticated actors.

Users of the Virtualizor software platform were exposed to potentially malicious updates due to the lack of cryptographic verification. System administrators should verify the integrity of their software packages to ensure they were not compromised during this window.

The takeaway

Developers and companies must prioritize cryptographically signed software updates to prevent interception during transit. Relying solely on routing security is insufficient when update distribution channels lack end-to-end integrity checks.

Further reading

Learn more about the latest threats and vulnerabilities in the Cybersecurity section.

Source note: This article includes information reported by RocketNews.

Live Poll

Do you trust that your software providers are adequately securing your data against infrastructure attacks?