VoidLink: The “Cloud-First” Malware Hunting Your Linux Servers
ID: ab402a8d-1646-5e46-b4e0-485e174059b8
STIX ID: report--ab402a8d-1646-5e46-b4e0-485e174059b8
Feed Name: securityonline.info
VoidLink is a commercial-grade, cloud-first malware framework discovered in December 2025 that targets Linux servers, Docker containers, and Kubernetes clusters. Written primarily in Zig with a modular Plugin API and a web dashboard, it ships with 30+ plugins for credential harvesting, anti-forensics, and more; employs adaptive stealth to detect EDR and deploy userland or eBPF-based rootkits; and is localized for Chinese speakers, suggesting China-affiliated developers and posing a significant supply-chain and cloud-infrastructure risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
