logo

New Linux malware targets the cloud, steals creds, and then vanishes

ID: 68558c5f-b697-5a67-b4c6-6bb5d8b3e090

STIX ID: report--68558c5f-b697-5a67-b4c6-6bb5d8b3e090

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

VoidLink is a newly identified Linux-first, cloud-native malware framework detailed by Check Point Research that targets cloud infrastructure (AWS, GCP, Azure, Alibaba, Tencent) and includes kernel-level rootkits, a custom API similar to Cobalt Strike's Beacon, and 30+ plugins for reconnaissance, credential and secrets theft, container discovery/escape, lateral movement, persistence, and anti-forensics; researchers characterize it as sophisticated and likely developed by professional actors but report no observed real-world infections so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.