logo

New threat actor, UAT-9921, leverages VoidLink framework in campaigns

ID: e05e644d-1c2e-507e-9abe-dcd2d3439ff4

STIX ID: report--e05e644d-1c2e-507e-9abe-dcd2d3439ff4

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-27

Author: Nick Biasini

...
...

Cisco Talos reports on UAT-9921 and VoidLink: a near-production, Linux-focused implant management framework employing compile-on-demand plugins, kernel-level rootkits, container/Kubernetes awareness and mesh P2P routing. UAT-9921 uses stolen credentials and Apache Dubbo RCE to compromise servers, deploy VoidLink implants, run SOCKS-based internal scanning and enable lateral movement; Talos observed victims from September through January 2026 and published Snort/ClamAV signatures to detect the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.