{"id":183229,"date":"2026-09-02T10:53:39","date_gmt":"2026-09-02T08:53:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/news\/atakuyushhie-ispolzovali-bgp-dlya-podmeny-servera-obnovlenij-virtualizor-i-sajta-softaculous"},"modified":"2026-09-02T10:53:42","modified_gmt":"2026-09-02T08:53:42","slug":"attackers-used-bgp-to-hijack-virtualizor-update-server-and-softaculous-website","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/attackers-used-bgp-to-hijack-virtualizor-update-server-and-softaculous-website","title":{"rendered":"Angreifer nutzten BGP zur Manipulation des Virtualizor-Update-Servers und der Softaculous-Website","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Die Angreifer konnten die Infrastruktur-Elemente des Unternehmens Softaculous manipulieren, indem sie eine falsche Route \u00fcber das BGP-Protokoll setzten, wodurch der Datenverkehr des Subnetzes von den Softaculous-Servern auf einen Server umgeleitet wurde, der unter der Kontrolle der Angreifer stand. Infolgedessen gelang es, Anfragen an die Kunden-Website des Unternehmens, das Abrechnungssystem und die Server zur Verteilung von Updates f\u00fcr die Software Virtualizor umzuleiten, um diese f\u00fcr die Verbreitung von Malware und Angriffe auf die Kunden des Unternehmens zu nutzen. Die Angreifer konnten \u00fcber den Dienst Let\u2019s Encrypt g\u00fcltige TLS-Zertifikate f\u00fcr die Domains von Softaculous erhalten, da die automatische \u00dcberpr\u00fcfung des Domainbesitzes \u00fcber die manipulierten Hosts erfolgreich war.         <\/p>\n<p>Das Unternehmen Softaculous bietet eine gleichnamige Plattform zur Automatisierung der Installation von Webanwendungen an, die in <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/control-panel\/\"   title=\"Hosting-Control Panels\" data-wpil-keyword-link=\"linked\">Hosting-Control Panels<\/a> cPanel, Plesk, DirectAdmin und ispmanager integriert ist, sowie den Website-Builder SitePad, das Hosting-Control Panel Webuzo, das Backup-System Backuply und das Virtualizor-Panel zur Verwaltung virtueller Server entwickelt. W\u00e4hrend des Angriffs gelang es den Angreifern, ein gef\u00e4lschtes Update f\u00fcr das Virtualizor-Panel zu ver\u00f6ffentlichen, das sch\u00e4dlichen Code enthielt. Die Zahl der Benutzer, die dieses Update installiert haben, ist bisher unklar.    <\/p>\n<p>Eine gef\u00e4lschte BGP-Ank\u00fcndigung, die die Routing-Informationen f\u00fcr das Subnetz 162.55.80.0\/24 ver\u00e4nderte, wurde aus dem autonomen System AS62390 (NexonHost) \u00fcber den Transitprovider AS6204 (Zet.net) gesendet. Die Routing-St\u00f6rung dauerte 33 Stunden vom 28. August 23:57 (MSK) bis zum 30. August 08:50 (MSK). Die Wahrscheinlichkeit, dass eine Anfrage w\u00e4hrend der Hochphase des Angriffs durch <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/server\/\"   title=\"Server\" data-wpil-keyword-link=\"linked\">Server<\/a> den Angreifer geleitet wurde, wurde auf 72 % gesch\u00e4tzt (266 von 368 BGP-Peers nutzten die gef\u00e4lschte Route).     <\/p>\n<p>Den Nutzern der Produkte von Softaculous, die \u00fcblicherweise Hosting-Provider sind, wird empfohlen, ihre Systeme auf Malware-Aktivit\u00e4ten zu \u00fcberpr\u00fcfen und das Passwort f\u00fcr den Zugriff auf die Softaculous-Dienste zu \u00e4ndern. Den Administratoren von Virtualizor wird geraten, ihre Systeme als potenziell kompromittiert zu betrachten und die API-Zugangsschl\u00fcssel sowie die Kundenschl\u00fcssel zu \u00e4ndern. Ein Indikator f\u00fcr eine Kompromittierung ist das Auftreten der Datei \u201e\/etc\/systemd\/system\/java-jre-update.service\u201c im System. Kunden, die w\u00e4hrend des Angriffs ihre Kreditkartennummern auf der Website softaculous.com\/clients eingegeben haben, sollten verd\u00e4chtige Transaktionen \u00fcberpr\u00fcfen.    <\/p>\n<p>Domains, die von dem Angriff betroffen sind:  <\/p>\n<ul>\n<li>a.softaculous.com,\n<li>ampps.com,\n<li>api.sitepad.com,\n<li>api.softaculous.com,\n<li>api.virtualizor.com,\n<li>api.webuzo.com,\n<li>backuply.com,\n<li>files.ampps.com,\n<li>files.sitepad.com,\n<li>files.softaculous.com,\n<li>files.virtualizor.com,\n<li>files.webuzo.com,\n<li>pagelayer.com,\n<li>popularfx.com,\n<li>server.softaculous.com,\n<li>sitepad.com,\n<li>softaculous.com,\n<li>virtualizor.com,\n<li>webuzo.com,\n<li>www.ampps.com,\n<li>www.backuply.com,\n<li>www.popularfx.com,\n<li>www.sitepad.com,\n<li>www.softaculous.com,\n<li>www.virtualizor.com,\n<li>www.webuzo.com.  <\/ul>\n<p>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=66196\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0441\u043c\u043e\u0433\u043b\u0438 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u044d\u043b\u0435\u043c\u0435\u043d\u0442\u044b \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Softaculous, \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0432 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u043e\u0433\u043e \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 \u0447\u0435\u0440\u0435\u0437 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b BGP, \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043f\u043e\u0434\u0441\u0435\u0442\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 Softaculous \u043d\u0430 \u043f\u043e\u0434\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u044b\u0439 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c \u0441\u0435\u0440\u0432\u0435\u0440. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0430\u0442\u0430\u043a\u0438, \u0441\u0440\u0435\u0434\u0438 \u043f\u0440\u043e\u0447\u0435\u0433\u043e, \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u044f \u043a \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u043c\u0443 web-\u0441\u0430\u0439\u0442\u0443 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438, \u0431\u0438\u043b\u043b\u0438\u043d\u0433\u0443 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0439 \u0434\u043b\u044f \u041f\u041e Virtualizor, \u043f\u043e\u0441\u043b\u0435 \u0447\u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0438\u0445 \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-183229","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0441\u043c\u043e\u0433\u043b\u0438 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u044d\u043b\u0435\u043c\u0435\u043d\u0442\u044b \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Softaculous, \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0432 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u043e\u0433\u043e \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 \u0447\u0435\u0440\u0435\u0437 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b BGP, \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043f\u043e\u0434\u0441\u0435\u0442\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 Softaculous.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Alexander Kovalev\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/attackers-used-bgp-to-hijack-virtualizor-update-server-and-softaculous-website\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b\u0438 BGP \u0434\u043b\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0439 Virtualizor \u0438 \u0441\u0430\u0439\u0442\u0430 Softaculous | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0441\u043c\u043e\u0433\u043b\u0438 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u044d\u043b\u0435\u043c\u0435\u043d\u0442\u044b \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Softaculous, \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0432 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u043e\u0433\u043e \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 \u0447\u0435\u0440\u0435\u0437 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b BGP, \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043f\u043e\u0434\u0441\u0435\u0442\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 Softaculous.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/attackers-used-bgp-to-hijack-virtualizor-update-server-and-softaculous-website\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-02T08:53:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-02T08:53:42+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Die Angreifer nutzten BGP, um den Update-Server von Virtualizor und die Softaculous-Website zu ersetzen | ProHoster","description":"Die Angreifer konnten die Infrastruktur von Softaculous manipulieren, indem sie einen falschen Pfad \u00fcber das BGP-Protokoll eingef\u00fcgt haben, wodurch der Verkehr des Subnetzes auf die Server von Softaculous umgeleitet wurde.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/attackers-used-bgp-to-hijack-virtualizor-update-server-and-softaculous-website","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b\u0438 BGP \u0434\u043b\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0439 Virtualizor \u0438 \u0441\u0430\u0439\u0442\u0430 Softaculous | ProHoster","og:description":"\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0441\u043c\u043e\u0433\u043b\u0438 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u044d\u043b\u0435\u043c\u0435\u043d\u0442\u044b \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Softaculous, \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0432 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u043e\u0433\u043e \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0430 \u0447\u0435\u0440\u0435\u0437 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b BGP, \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043f\u043e\u0434\u0441\u0435\u0442\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 Softaculous.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/attackers-used-bgp-to-hijack-virtualizor-update-server-and-softaculous-website","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-09-02T08:53:39+00:00","article:modified_time":"2026-09-02T08:53:42+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/183229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=183229"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/183229\/revisions"}],"predecessor-version":[{"id":183230,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/183229\/revisions\/183230"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=183229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=183229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=183229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}