logo

VoidLink Malware Exhibits Multi-Cloud Capabilities and AI Code

ID: 0dab60fe-acf6-5cec-82e7-a15912ca2a1f

STIX ID: report--0dab60fe-acf6-5cec-82e7-a15912ca2a1f

Feed Name: Infosecurity Magazine (News)

Threat Score
76/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

...
...

VoidLink is a Linux C2 implant designed for long-term intrusions across cloud and enterprise environments: it fingerprints AWS/GCP/Azure/Alibaba/Tencent, harvests credentials (env vars, SSH keys, shell history, Kubernetes secrets), supports container escape and Kubernetes privilege escalation, and employs kernel-level stealth (eBPF/LKM/userland hooking). The modular agent uses AES-256-GCM over HTTPS for C2 and contains unusual development artefacts (duplicated phase labels, verbose logs) that suggest AI-assisted coding; researchers report it as an operational implant with live infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.