logo

New China Linked VoidLink Linux Malware Targets Major Cloud Providers

ID: 5775abef-778a-5b28-a5d6-cee8ebd9479c

STIX ID: report--5775abef-778a-5b28-a5d6-cee8ebd9479c

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

VoidLink is a sophisticated, cloud-native Linux malware framework discovered by Check Point Research that specifically targets major cloud providers (AWS, GCP, Azure, Alibaba, Tencent), hunts for credentials (SSH keys, Git logins), hides inside containers (Docker, Kubernetes), and employs multiple kernel- and user-space stealth techniques (LD_PRELOAD, eBPF, LKM) along with a modular 37-plugin architecture and a custom VoidStream protocol to exfiltrate data; researchers link it to a likely Chinese-affiliated group, note high technical polish and a Chinese-language control dashboard, and warn organizations to bolster cloud defenses despite no confirmed victims so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.