logo

VoidLink Malware Framework Attacking Kubernetes and AI Workloads

ID: 42ab6413-f8d3-57d1-8554-bf72a0fe9e6f

STIX ID: report--42ab6413-f8d3-57d1-8554-bf72a0fe9e6f

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

VoidLink is a sophisticated, cloud-native Linux malware framework disclosed by Check Point Research and observed in active campaigns by Cisco Talos; it targets containers and cloud workloads on major cloud platforms, uses fileless execution and kernel-evasive techniques, and can harvest cloud metadata, API credentials, and other secrets while adapting its behavior based on the environment. Its compile-on-demand capability and stealthy persistence make it a high-risk threat to Kubernetes and containerized AI/cloud workloads, prompting recommendations for kernel-level monitoring (eBPF), credential rotation, and tightened pod permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.