logo

Unveiling VoidLink – A Stealthy, Cloud-Native Linux Malware Framework

ID: 7a032639-0701-5df9-a63b-7c2018fae168

STIX ID: report--7a032639-0701-5df9-a63b-7c2018fae168

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-27

Author: [email protected]

...
...

**Executive summary:** Check Point Research describes VoidLink, a rapidly evolving, cloud-first Linux malware framework written in Zig that provides a modular plugin system, kernel- and user-mode rootkits (LD_PRELOAD, LKM, eBPF), adaptive evasion, multiple C2 transports (HTTP/HTTPS, DNS, ICMP, mesh), credential- and secret-harvesting modules, and an operator dashboard with build-on-demand capabilities; while highly capable and potentially commercially intended, the report notes development artifacts and no confirmed real-world infections to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.