VoidLink Malware Framework Targets Kubernetes and AI Workloads in New Cyber Attack Wave
ID: 07f0e0eb-dcdb-57fe-9243-61959392cf81
STIX ID: report--07f0e0eb-dcdb-57fe-9243-61959392cf81
Feed Name: GBHackers
VoidLink is a purpose-built Linux malware framework identified by Cisco Talos (and disclosed by Check Point Research) that targets cloud-native environments—containers, Kubernetes pods, GPU clusters and VMs—by fingerprinting hosting environments, harvesting credentials and metadata, and using in-memory, fileless techniques (rootkit-like tricks, self-modifying code, anti-analysis) to evade traditional agent- and log-based defenses; it is linked to an advanced actor (UAT-9921) and signals a broader shift toward AI-aware, workload-targeting offensive frameworks, prompting recommendations to adopt kernel-level, eBPF-based runtime telemetry and enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
