logo

VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits

ID: 8ed9e584-3144-5c16-9801-f129a8716285

STIX ID: report--8ed9e584-3144-5c16-9801-f129a8716285

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2026-01-16

Date Updated: 2026-05-01

...
...

This report analyzes VoidLink, a sophisticated Chinese‑developed Linux malware framework targeting cloud and container environments that uses a three‑stage, largely fileless loader, adaptive profiling to evade EDR/CDR, and a novel serverside rootkit compilation (SRC) capability to produce kernel modules tailored to each victim kernel. VoidLink provides kernel‑level stealth via eBPF and LKM techniques, multiple control channels including an ICMP covert channel and a prctl magic interface, embeds cloud/container escape and Kubernetes privilege escalation plugins, and includes detailed IOCs (hashes, C2 IP/endpoints, file and process artifacts) and recommended runtime detection and mitigation controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.