VoidLink
- Malware type
- rootkit, credential-stealer, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-18 21:17:38
- Profile updated
- 2026-07-07 13:17:41
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Context
VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized environments. It features a plugin-based architecture with dynamically loadable components that provide reconnaissance, credential harvesting, privilege escalation, lateral movement, persistence, and anti-forensic capabilities. The framework demonstrates strong operational security through runtime encryption, environment awareness (cloud provider and container detection), and the use of user-mode and kernel-level rootkit techniques to evade detection. VoidLink is not a repurposed legacy tool but a purpose-built framework optimized for cloud infrastructure, indicating a shift in advanced threat development toward Linux-based cloud workloads. Although no confirmed large-scale infections have been observed, its maturity and design suggest potential use by sophisticated threat actors for long-term, stealthy access to cloud environments.
Reports & references
- Cisco Talos — Voidlink (report)
- isovalent.com — Voidlink Cloud Malware Detection (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Voidlink (report)
- research.checkpoint.com — Voidlink Early Ai Generated Malware Framework (report)
- sysdig.com — Voidlink Threat Analysis Sysdig Discovers C2 Compiled Kernel Rootkits (report)
- research.checkpoint.com — Voidlink The Cloud Native Malware Framework (report)