VoidLink is a modular, cloud-native Linux malware framework and rootkit platform, written primarily in Zig, designed for Linux servers, containers, Kubernetes workloads, and cloud environments. First publicly documented in January 2026, it combines loadable kernel modules, eBPF programs, and user-space techniques to conceal processes, files, kernel modules, and network activity while supporting remote operator control. It can execute components filelessly from memory, profile host security products and cloud environments, detect containers and major cloud providers, and dynamically select functionality based on kernel version and the compromised environment.
VoidLink’s rootkit subsystem uses kernel syscall-table patching on older systems and ftrace-based hooks on newer kernels. Its eBPF component tampers with Netlink diagnostic responses to hide selected connections from common socket-inspection utilities. The framework includes an ICMP-based covert command channel supporting concealment of processes, ports, and network addresses, privilege elevation for selected processes, configuration changes, and self-destruction. Later variants added delayed activation, anti-debugging and forensic-tool detection, protected-process signal suppression, module masquerading, runtime code encryption, self-deletion, and persistence mechanisms intended to protect fileless implants.
The framework contains more than 30 post-exploitation plugins, including functionality for cloud and container enumeration, Kubernetes service-account token discovery, container-escape probing, and Kubernetes privilege-escalation assessment. VoidLink has been linked with moderate confidence to Chinese-speaking operators based on Simplified Chinese development annotations and associated infrastructure. Development artifacts indicate that a single developer used AI-assisted, specification-driven workflows to build the framework rapidly.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco Talos recently discovered a new threat actor, UAT-9221, leveraging VoidLink in campaigns.
A newly tracked intrusion framework called VoidLink is drawing attention for its modular design and focus on Linux systems. It behaves like an implant management framework, letting operators deploy a core implant and add capabilities as needed...
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The operator interacts with the rootkit through a Python script, icmp_ctl.py, which constructs and sends the ICMP packets using raw sockets.
Finally, load_lkm.sh provided boot-time persistence with a particularly interesting feature: It scanned /proc/*/exe for processes running from memfd file descriptors, a telltale sign of fileless implants.
Finally, load_lkm.sh provided boot-time persistence with a particularly interesting feature: It scanned /proc/*/exe for processes running from memfd file descriptors, a telltale sign of fileless implants.
The rootkit components masquerade under the module name vl_stealth (or amd_mem_encrypt). The load_lkm.sh script provides boot-time persistence and loads /root/kernel5x_new/vl_stealth.ko.
The GIVE_ROOT command (0x11) is noteworthy: It takes a target PID as an argument and uses prepare_creds()/commit_creds() to set all UID and GID fields to zero for that process, effectively granting it root privileges without any authentication mechanism.
VoidLink combines a traditional LKM with eBPF programs in a hybrid design; the LKM handles deep kernel manipulation while eBPF hides network connections from ss. | The companion eBPF program hides network connections from the ss utility by manipulating Netlink socket responses in userspace memory. | The LKM performs syscall hooking via ftrace, process hiding via getdents64 syscall hooking, file filtering via vfs_read, and network hiding via seq_show kretprobes.
The ICMP command payload is XOR-encrypted with a single-byte key, 0x42 by default. The v5 variant also XOR-encrypts the module name string and decodes it at runtime.
Every VoidLink variant disguises its kernel module metadata to impersonate a legitimate AMD driver, using the author 'Advanced Micro Devices, Inc.' and description 'AMD Memory Encryption Support.'
One notable detail: The variant suppresses all kernel log output by redefining pr_info, pr_err, and pr_warn as no-ops, a simple but effective anti-forensics measure.
The CentOS 7 variant includes a self-destruct command, and the phase notes describe log cleanup as part of its stealth enhancements.
The entire malicious logic exists as transient, encrypted blobs in memory, re-decrypted only when it needs to "beacon" back to the C2 server.
Check Point's analysis revealed VoidLink to be a sophisticated, modular command-and-control framework written in Zig, featuring cloud-environment detection...
VoidLink's v5 variant defers all hook installation by three seconds. The module initially appears loaded and benign, with no hooks, Netfilter registrations, or kretprobes.
The rootkit directly modifies kernel behavior through a malicious LKM, including ftrace redirection, Netfilter command interception, syscall manipulation, and signal-delivery interception.
The rootkit hides processes via getdents64 syscall hooking, removes itself from the kernel module list, filters /proc/kallsyms and /proc/modules, and hides network connections from netstat and ss.
The loader scans for processes running from memfd and passes their PIDs to the rootkit, allowing an already running fileless implant to be hidden immediately after activation.
the framework supports multiple stealth mechanisms, including Loadable Kernel Module (LKM) rootkits, LD_PRELOAD user-space persistence techniques, and eBPF-based capabilities.
they can manipulate the kernel’s internal function pointers. Specifically, they can overwrite the handler for the getdents64 syscall.
VoidLink's approach uses a kernel timer that fires every five seconds and iterates over the entire process list... for_each_process(task) { if (is_debug_tool(task->comm))
Before deciding what to do, it profiles the environment it's running in. It can identify major cloud providers—including AWS, Microsoft Azure, Google Cloud Platform, Alibaba Cloud, and Tencent Cloud—as well as determine whether it's running inside Docker containers or Kubernetes workloads.
Before loading the rootkit, load_lkm.sh scans /proc/*/exe and uses readlink to identify processes executing from memfd file descriptors.
Check Point's analysis revealed VoidLink to be a sophisticated, modular command-and-control framework written in Zig, featuring cloud-environment detection...
VoidLink's v5 variant defers all hook installation by three seconds. The module initially appears loaded and benign, with no hooks, Netfilter registrations, or kretprobes.
In January 2026, Check Point Research (CPR) exposed VoidLink, a Linux-based malware framework featuring modular command-and-control (C2) architecture, eBPF and LKM rootkits, cloud and container enumeration, and more than 30 post-exploitation plugins.
It can identify major cloud providers—including AWS, Microsoft Azure, Google Cloud Platform, Alibaba Cloud, and Tencent Cloud
one developer used an AI environment to produce VoidLink, an 88,000-line command-and-control offensive framework, in under a week.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
82 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated Analytic Story: VoidLink Cloud-Native Linux Malware.
A malware referenced as combining fileless execution with a rootkit; its loader identifies processes running from memfd and supplies their PIDs to the rootkit so an active fileless implant can be hidden after activation.
Linux eBPF rootkit that hides active TCP connections from ss by using bpf_probe_write_user() to tamper with Netlink response buffers in user space, causing parsers to skip socket records for hidden ports.
An 88,000-line offensive command-and-control framework reportedly produced with the help of an AI environment in under a week.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.