VoidLink Rootkit Leverages eBPF and Kernel Modules to Stealthily Infiltrate Linux Systems
ID: 3f6665bd-edfc-5e6c-86fc-caa49f1d203f
STIX ID: report--3f6665bd-edfc-5e6c-86fc-caa49f1d203f
Feed Name: GBHackers
VoidLink is a sophisticated cloud-focused Linux rootkit framework that pairs traditional loadable kernel modules (vlstealth / amdmemencrypt) with companion eBPF programs to hide processes, files, modules, and network ports across CentOS 7 through Ubuntu 22.04. It implements ftrace hooks, Netfilter interception, and a covert ICMP-based command channel (magic ID 0xC0DE, single-byte XOR) for persistence and control, includes delayed initialization and anti-forensics, and was reconstructed from leaked development artifacts and vendor analyses; defenders are advised to enforce Secure Boot/signed modules, limit eBPF capabilities, monitor module load syscalls, and perform integrity checks from a trusted environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
