UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors
ID: a77e0191-8ad5-544b-ab79-d05410bdc0e4
STIX ID: report--a77e0191-8ad5-544b-ab79-d05410bdc0e4
Feed Name: The Hacker News
VoidLink is a modular, multi-language malware framework (Zig implant, C plugins, Go backend) observed in operations by a threat actor labelled UAT-9921; it provides compile-on-demand plugins, kernel-level rootkit components, stealth/evasion features, a SOCKS proxy for internal reconnaissance, and RBAC for operator roles. Cisco Talos and other vendors link VoidLink activity to multiple victims (technology and financial sectors) with evidence of operations since 2019 and confirmed victims from September 2025, making it a production-ready, high-risk tool for persistent cloud-focused intrusion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
