UAT-9921

Aliases: UAT-9921, VoidLink Operator

First seen
2019-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:25:19

Targeted industries: technology-and-telecommunications financial-services energy-and-utilities

Context

UAT-9921 is a China-nexus threat actor active since 2019, tracked by Cisco Talos. In 2026, they were observed deploying 'VoidLink', a sophisticated modular framework primarily targeting Linux systems (IoT, Critical Infrastructure). Unique characteristics include the use of AI-enabled IDEs for rapid development (ZigLang implant, GoLang backend), P2P mesh networking for C2, and advanced persistence via eBPF rootkits. They target Technology and Financial sectors exploiting Java serialization vulnerabilities (Apache Dubbo).

Reports & references

  • Cisco Talos — Voidlink (report)
  • isovalent.com — Voidlink Cloud Malware Detection (report)

External references