New threat actor UAT-9921 deploys VoidLink against enterprise sectors
ID: 1f1c03ee-2b65-534b-9032-d1e2216a51f6
STIX ID: report--1f1c03ee-2b65-534b-9032-d1e2216a51f6
Feed Name: Security Affairs
Threat Score
Cisco Talos uncovered a previously unknown threat actor tracked as UAT-9921 using a modular, Linux-focused attack framework called VoidLink to target technology and financial firms; VoidLink features compile-on-demand plugins, eBPF/LKM rootkits, container escape, privilege escalation, cloud awareness, EDR evasion, and a mesh peer-to-peer design, and has been linked to multiple victims from 2019 through January 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
