logo

New VoidLink malware framework targets Linux cloud servers

ID: 668e759e-a1e8-5be4-bf23-7b55fecafa9a

STIX ID: report--668e759e-a1e8-5be4-bf23-7b55fecafa9a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**VoidLink — cloud-native Linux malware framework**: Check Point researchers describe VoidLink, a sophisticated, actively developed modular Linux malware framework targeting cloud and container environments; it includes plugins for reconnaissance, credential harvesting, lateral movement, persistence and anti-forensics, uses rootkits (LD_PRELOAD, LKMs, eBPF) to hide activity, and adapts behavior when running in Docker/Kubernetes or enumerating cloud metadata. The report includes technical details and IoCs but notes no confirmed active infections, suggesting the framework may be a commercial product or targeted toolkit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.