logo

UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors

ID: a77e0191-8ad5-544b-ab79-d05410bdc0e4

STIX ID: report--a77e0191-8ad5-544b-ab79-d05410bdc0e4

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

VoidLink is a modular, multi-language malware framework (Zig implant, C plugins, Go backend) observed in operations by a threat actor labelled UAT-9921; it provides compile-on-demand plugins, kernel-level rootkit components, stealth/evasion features, a SOCKS proxy for internal reconnaissance, and RBAC for operator roles. Cisco Talos and other vendors link VoidLink activity to multiple victims (technology and financial sectors) with evidence of operations since 2019 and confirmed victims from September 2025, making it a production-ready, high-risk tool for persistent cloud-focused intrusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.