Attackers Hijacked Softaculous to Distribute Malware
Cybercriminals manipulated internet routing to poison software updates over a 33-hour period.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust that your software providers are adequately securing your data against infrastructure attacks?
Attackers hijacked Softaculous network infrastructure by seizing an IP address block to distribute malicious software. The incident involved two separate hijacking episodes that went undetected for 22 hours.
Why it matters
The breach occurred because Softaculous failed to use cryptographically verified updates, allowing attackers to intercept and compromise files. Vulnerabilities in BGP routing security and ineffective validation at transit providers enabled the exploit.
The attackers seized the 162.55.80.0/24 IP address block using RPKI-valid announcements with forged origin AS paths. The intrusion leveraged weaknesses in TLS certificate acquisition and BGP routing protocols.
The players
Softaculous
A UAE-based company providing software auto-installers that failed to implement code signing for updates.
Hetzner Online
A web hosting provider that hosted the compromised IP space and responded to the routing hijacking.
Zet.net
A network transit provider that, alongside Softaculous, failed to detect the unauthorized routing for 22 hours.
The details
The attackers intercepted and poisoned Virtualizor software updates while bypassing standard security checks. Hosting provider Hetzner Online required 12 hours to address the first hijacking and nearly 10 hours for the second attempt.
Timeline
September 2026: Attackers hijacked Softaculous network infrastructure.
The Tech Race
This incident highlights how legacy weaknesses in global routing protocols continue to outpace modern authentication efforts. It exposes the structural vulnerability of relying on RPKI validation when origin paths can be forged by sophisticated actors.
Users of the Virtualizor software platform were exposed to potentially malicious updates due to the lack of cryptographic verification. System administrators should verify the integrity of their software packages to ensure they were not compromised during this window.
The takeaway
Developers and companies must prioritize cryptographically signed software updates to prevent interception during transit. Relying solely on routing security is insufficient when update distribution channels lack end-to-end integrity checks.
Further reading
Learn more about the latest threats and vulnerabilities in the Cybersecurity section.
Source note: This article includes information reported by RocketNews.
Live Poll
Do you trust that your software providers are adequately securing your data against infrastructure attacks?







