New threat actor, UAT-9921, leverages VoidLink framework in campaigns
ID: e05e644d-1c2e-507e-9abe-dcd2d3439ff4
STIX ID: report--e05e644d-1c2e-507e-9abe-dcd2d3439ff4
Feed Name: Cisco Talos
Cisco Talos reports on UAT-9921 and VoidLink: a near-production, Linux-focused implant management framework employing compile-on-demand plugins, kernel-level rootkits, container/Kubernetes awareness and mesh P2P routing. UAT-9921 uses stolen credentials and Apache Dubbo RCE to compromise servers, deploy VoidLink implants, run SOCKS-based internal scanning and enable lateral movement; Talos observed victims from September through January 2026 and published Snort/ClamAV signatures to detect the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
