New China Linked VoidLink Linux Malware Targets Major Cloud Providers
ID: 5775abef-778a-5b28-a5d6-cee8ebd9479c
STIX ID: report--5775abef-778a-5b28-a5d6-cee8ebd9479c
Feed Name: HackRead
VoidLink is a sophisticated, cloud-native Linux malware framework discovered by Check Point Research that specifically targets major cloud providers (AWS, GCP, Azure, Alibaba, Tencent), hunts for credentials (SSH keys, Git logins), hides inside containers (Docker, Kubernetes), and employs multiple kernel- and user-space stealth techniques (LD_PRELOAD, eBPF, LKM) along with a modular 37-plugin architecture and a custom VoidStream protocol to exfiltrate data; researchers link it to a likely Chinese-affiliated group, note high technical polish and a Chinese-language control dashboard, and warn organizations to bolster cloud defenses despite no confirmed victims so far.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
