logo

VoidLink Malware Puts Cloud Systems on High Alert With Custom Built Attacks

ID: d111d61b-c7d7-5d2c-a324-993ac2de0298

STIX ID: report--d111d61b-c7d7-5d2c-a324-993ac2de0298

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

VoidLink is a sophisticated, cloud-focused malware framework that dynamically compiles custom kernel rootkits on the attacker C2 (Serverside Rootkit Compilation) tailored to each victim's kernel, enabling stable eBPF/LKM payloads; it is written in Zig, executes filelessly in memory via memfd_create/execveat, uses covert ICMP communication, probes and evades multiple security products, and includes container/Kubernetes escape capabilities—researchers note it was found in an in-progress build with debug symbols, offering detection opportunities by monitoring abnormal memory activity or unauthorized kernel module loading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.