New Chinese-Made Malware Framework Targets Linux-Based Cloud Environments
ID: 832275ee-eaa2-5bf8-9b69-65c9e2f94bb6
STIX ID: report--832275ee-eaa2-5bf8-9b69-65c9e2f94bb6
Feed Name: Infosecurity Magazine (News)
Check Point Research discovered VoidLink, a sophisticated, modular Linux malware C2 framework written in Zig and actively developed by Chinese-speaking authors; it includes custom loaders, implants, rootkits and ~37 plugins enabling reconnaissance, persistence, container escapes, secret extraction, lateral movement and cloud-provider detection across AWS, GCP, Azure, Alibaba and Tencent. Documentation and artifacts indicate active development and commercial intent, but researchers have not observed confirmed real-world infections; defenders are advised to harden Linux, cloud and container environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
