Hackers hijack internet routing using BGP to redirect update traffic for the Virtualizor VPS management platform, then use that diverted traffic to deliver a malicious Virtualizor package. Multiple reports say the malicious update establishes persistent root-level access on affected systems. An incident window is described as starting around August 28 at 20:57.

Both outlets describe a coordinated approach: BGP routing is manipulated to divert Softaculous-related traffic and Virtualizor update requests away from legitimate servers and toward attacker-controlled infrastructure. After victims receive the altered update, the compromise enables root access. One account from a hosting provider adds that, among the hypervisors it checked, a subset experienced root-level compromise, with figures reported as 5 out of 34. The reports focus on the mechanism—routing hijack followed by malicious update delivery—while providing limited independent detail on the full scope and affected customer populations.

Authorities and Virtualizor/hosting-provider communications referenced in the reports emphasize the delivery path and the resulting persistence, but the extent of total exposure is not fully established in the coverage.