VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems
ID: cf3b185a-84b4-5550-a1a8-e8c451c446ef
STIX ID: report--cf3b185a-84b4-5550-a1a8-e8c451c446ef
Feed Name: cybersecurityNews.com
A new, technically advanced Linux rootkit named VoidLink uses a hybrid LKM + eBPF architecture to hide processes, files, and network connections on cloud hosts; it is modular (30+ plugins), written in Zig, employs a covert ICMP command channel, and impersonates legitimate AMD memory driver module names such as `vl_stealth` and `amd_mem_encrypt`. Analysis of a leaked data dump produced source code, binaries, deployment scripts, and IOCs including Alibaba Cloud IPs `8.149.128.10` and `116.62.172.147`, suggesting a Chinese-speaking operator; the report details advanced eBPF techniques to hide `ss` output, anti-forensics features, and recommends mitigations like Secure Boot, kernel module signing, kernel lockdown, auditing module syscalls, restricting `bpf()` and cross-referencing `ps`, `ss`, and `/proc`.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
