logo

VoidLink: The “Cloud-First” Malware Hunting Your Linux Servers

ID: ab402a8d-1646-5e46-b4e0-485e174059b8

STIX ID: report--ab402a8d-1646-5e46-b4e0-485e174059b8

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

VoidLink is a commercial-grade, cloud-first malware framework discovered in December 2025 that targets Linux servers, Docker containers, and Kubernetes clusters. Written primarily in Zig with a modular Plugin API and a web dashboard, it ships with 30+ plugins for credential harvesting, anti-forensics, and more; employs adaptive stealth to detect EDR and deploy userland or eBPF-based rootkits; and is localized for Chinese speakers, suggesting China-affiliated developers and posing a significant supply-chain and cloud-infrastructure risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.