VoidLink Framework Introduces On-Demand Tool Generation with Native Windows Plugin Support
ID: 807dd75c-41f6-5ff0-80f0-65d489c54526
STIX ID: report--807dd75c-41f6-5ff0-80f0-65d489c54526
Feed Name: GBHackers
Cisco Talos links a sophisticated, cloud-native malware framework called VoidLink to the actor UAT-9921; VoidLink uses a Zig/C/Go stack with on-demand compilation of kernel modules and plugins, supports eBPF/LKM rootkits, container privilege escalation and sandbox escape, and is cloud-aware (detecting Kubernetes/Docker and querying metadata APIs). The actor compromises internet-facing servers (via pre-obtained credentials and Apache Dubbo Java serialization RCE), deploys VoidLink implants and SOCKS proxies to perform internal reconnaissance and lateral movement, and has been observed in active campaigns with vendor detections (Snort signatures, ClamAV) available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
