logo

Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

ID: 946d6aa8-7e1c-504c-a23f-6e52e699096e

STIX ID: report--946d6aa8-7e1c-504c-a23f-6e52e699096e

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2026-03-26

Date Updated: 2026-04-27

...
...

## Executive summary This report analyzes leaked source code and binaries for VoidLink, a sophisticated hybrid Linux kernel rootkit (LKM + eBPF) that provides process and network hiding, an ICMP-based covert command channel with runtime credential rotation, privilege escalation, anti-forensics/anti-debugging, delayed hook initialization, and integration with fileless implants; the dump contains multi-generation development artifacts, compiled .ko files, Alibaba Cloud operator IPs, and detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.