logo

VoidLink Framework Enables On-Demand Tool Generation with Windows Plugin Support

ID: 22f4efc0-e817-5b0a-9c3d-844cf254177c

STIX ID: report--22f4efc0-e817-5b0a-9c3d-844cf254177c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

VoidLink is a modular implant management framework focused on Linux that supports compile-on-demand plugins (targeting different distros), advanced evasion (e.g., eBPF/LKM rootkit behavior), container/Kubernetes awareness, and post-compromise tooling such as SOCKS servers and scanning; Cisco Talos links it to actor UAT-9921 with victims observed from September through January 2026. Initial access in observed cases involved pre-obtained credentials and Java deserialization/Dubbo flaws, and Talos published detections (Snort SIDs 65915–65922, 65834–65842, and ClamAV Unix.Trojan.VoidLink-10059283); defenders should rotate exposed credentials, patch Java services, and monitor for SOCKS services, unusual scanning, and new outbound beacons.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.