logo

Analysis of VoidLink: A Cloud-Native Malware Threat Targeting Linux Systems

ID: 9f7d33aa-acf8-567f-bf3e-9f48a501118d

STIX ID: report--9f7d33aa-acf8-567f-bf3e-9f48a501118d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Check Point Research describes VoidLink, a highly sophisticated Linux malware framework engineered for cloud-native environments. VoidLink is modular (37+ plugins), written in Zig with multiple loaders and rootkit options (LD_PRELOAD, eBPF, LKM), performs cloud and container reconnaissance (AWS, GCP, Azure, Alibaba, Tencent, Docker, Kubernetes), uses runtime code encryption and adaptive OPSEC measures, and includes a web-based operator dashboard supporting multi-protocol C2; samples show active development but no confirmed widespread infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.