logo

New Chinese-Made Malware Framework Targets Linux-Based Cloud Environments

ID: 832275ee-eaa2-5bf8-9b69-65c9e2f94bb6

STIX ID: report--832275ee-eaa2-5bf8-9b69-65c9e2f94bb6

Feed Name: Infosecurity Magazine (News)

Threat Score
65/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

...
...

Check Point Research discovered VoidLink, a sophisticated, modular Linux malware C2 framework written in Zig and actively developed by Chinese-speaking authors; it includes custom loaders, implants, rootkits and ~37 plugins enabling reconnaissance, persistence, container escapes, secret extraction, lateral movement and cloud-provider detection across AWS, GCP, Azure, Alibaba and Tencent. Documentation and artifacts indicate active development and commercial intent, but researchers have not observed confirmed real-world infections; defenders are advised to harden Linux, cloud and container environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.