logo

VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems

ID: cf3b185a-84b4-5550-a1a8-e8c451c446ef

STIX ID: report--cf3b185a-84b4-5550-a1a8-e8c451c446ef

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A new, technically advanced Linux rootkit named VoidLink uses a hybrid LKM + eBPF architecture to hide processes, files, and network connections on cloud hosts; it is modular (30+ plugins), written in Zig, employs a covert ICMP command channel, and impersonates legitimate AMD memory driver module names such as `vl_stealth` and `amd_mem_encrypt`. Analysis of a leaked data dump produced source code, binaries, deployment scripts, and IOCs including Alibaba Cloud IPs `8.149.128.10` and `116.62.172.147`, suggesting a Chinese-speaking operator; the report details advanced eBPF techniques to hide `ss` output, anti-forensics features, and recommends mitigations like Secure Boot, kernel module signing, kernel lockdown, auditing module syscalls, restricting `bpf()` and cross-referencing `ps`, `ss`, and `/proc`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.