UAT-9921 is a threat actor tracked since at least 2019 and associated with deployment of the modular VoidLink intrusion framework. The actor has been observed targeting organizations primarily in the technology and financial services sectors, with operations centered on Linux environments and indications of possible Windows tooling as well. Available evidence indicates likely Chinese-language knowledge, but public reporting stops short of a definitive state attribution. UAT-9921 gains initial access through pre-obtained or stolen credentials and by exploiting Java serialization vulnerabilities, including Apache Dubbo-related weaknesses. After compromise, the actor installs VoidLink on servers to establish command and control, maintain stealthy post-compromise access, and support follow-on operations. Observed activity includes deploying SOCKS proxy capability, conducting broad internal and external network scanning, and using open-source tooling such as Fscan for reconnaissance and lateral movement. VoidLink is a Linux-focused, single-file, modular framework with compile-on-demand plugins tailored to different target environments. Reported capabilities include information gathering, lateral movement, anti-forensics, EDR detection and evasion, anti-analysis, mesh peer-to-peer traffic relaying, cloud and container awareness, privilege escalation, and advanced Linux tradecraft such as eBPF or loadable-kernel-module rootkit functionality. The framework also includes role-based access control and auditing features, suggesting a comparatively mature operational model. Researchers have noted signs that VoidLink development was assisted by AI-enabled coding tools, though this does not indicate autonomous AI-driven operations by the actor itself. UAT-9921 appears to use VoidLink primarily as a post-exploitation platform for persistence, stealth, reconnaissance, and expansion within victim environments rather than as an initial access tool. Victimology and tradecraft indicate an opportunistic but technically capable intrusion set focused on enterprise server environments, especially those exposed through weak credential hygiene or vulnerable Java services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Runs campaigns leveraging the VoidLink framework (details not provided in the newsletter snippet).
Newly identified activity cluster reported deploying the VoidLink framework in campaigns targeting enterprise sectors.
Cluster leveraging the VoidLink framework for server compromise, assessed to have Chinese-language knowledge; uses stolen credentials and Java deserialization RCE (notably Apache Dubbo) and possibly malicious documents for initial access.
Uses the modular VoidLink framework (primarily Linux-focused, with possible Windows implants) to compromise enterprise servers, establish C2, hide activity, and perform internal/external network scanning; initial access via stolen credentials and exploitation of Java serialization flaws (e.g., Apache Dubbo).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.