logo

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

ID: 1f1c03ee-2b65-534b-9032-d1e2216a51f6

STIX ID: report--1f1c03ee-2b65-534b-9032-d1e2216a51f6

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco Talos uncovered a previously unknown threat actor tracked as UAT-9921 using a modular, Linux-focused attack framework called VoidLink to target technology and financial firms; VoidLink features compile-on-demand plugins, eBPF/LKM rootkits, container escape, privilege escalation, cloud awareness, EDR evasion, and a mesh peer-to-peer design, and has been linked to multiple victims from 2019 through January 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.