logo

VoidLink Malware Framework Targets Kubernetes and AI Workloads in New Cyber Attack Wave

ID: 07f0e0eb-dcdb-57fe-9243-61959392cf81

STIX ID: report--07f0e0eb-dcdb-57fe-9243-61959392cf81

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

VoidLink is a purpose-built Linux malware framework identified by Cisco Talos (and disclosed by Check Point Research) that targets cloud-native environments—containers, Kubernetes pods, GPU clusters and VMs—by fingerprinting hosting environments, harvesting credentials and metadata, and using in-memory, fileless techniques (rootkit-like tricks, self-modifying code, anti-analysis) to evade traditional agent- and log-based defenses; it is linked to an advanced actor (UAT-9921) and signals a broader shift toward AI-aware, workload-targeting offensive frameworks, prompting recommendations to adopt kernel-level, eBPF-based runtime telemetry and enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.