VoidLink Linux C2 Uses LLM-Generated Malware with Kernel-Level Stealth
ID: 11b32d9f-608b-505f-94cc-5069e5f2d79c
STIX ID: report--11b32d9f-608b-505f-94cc-5069e5f2d79c
Feed Name: GBHackers
VoidLink is a sophisticated Linux command-and-control implant that harvests credentials from multiple cloud providers, detects and escapes container environments (Docker/Podman/Kubernetes) via specialized plugins, and uses adaptive rootkit techniques (eBPF, loadable kernel modules, or userland hooking) to maintain stealth and persistence; it communicates over AES-256-GCM-encrypted HTTPS to a hardcoded C2 (8.149.128.10) and shows signs of being produced with LLM assistance, lowering the barrier for capable malware development against cloud/container environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
