logo

VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits

ID: 27a3db26-5a28-515f-a949-f3562493400f

STIX ID: report--27a3db26-5a28-515f-a949-f3562493400f

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2026-01-16

Date Updated: 2026-05-01

...
...

**Executive summary:** Sysdig TRT analyzed VoidLink, a sophisticated Linux malware framework that uses a three-stage fileless loader (written in Zig), serverside rootkit compilation to produce kernel modules tailored to victim kernels, eBPF/LKM-based stealth hooks, adaptive EDR/CDR profiling, ICMP covert control, and cloud-native escape/privesc plugins; the report includes IOCs (hashes, C2 IP and endpoints, file and process artifacts) and detection/mitigation recommendations for runtime monitoring and kernel/eBPF auditing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.