A new cloud-focused malware framework, dubbed VoidLink, has emerged and is causing concern in the cybersecurity community. VoidLink targets Linux systems in cloud environments and stands out for its advanced detection evasion and self-deletion capabilities, making it particularly difficult to detect and analyze.

Built for Cloud: Targeting AWS, GCP, Azure and beyond
VoidLink is written in the Zig and is designed to recognize major cloud environments, such as AWS, GCP, Azure, Alibaba, and Tencent, and adapt its behavior depending on the platform.
Additionally, it can detect whether it is running inside Kubernetes or Docker containers, allowing attackers to optimize the attack and remain undetected. According to Check Point, the first samples of VoidLink were detected in December 2025 and appear to come from a Chinese development environment, suggesting that the framework is still in development.
See also: What lessons did we learn from the 2025 cyberattacks and the use of AI?
VoidLink functionality: More than 37 plugins
VoidLink comes with over 37 plugins, organized into categories such as identification, credential harvesting, lateral movement, and persistence. These plugins are loaded into memory at runtime and allow attackers to gain access to sensitive data such as cloud credentials and Git systems.
Credential harvesting enables attackers to gain access to critical development infrastructure and cloud system secrets, paving the way for espionage or supply chain attacks.

Adaptive stealth deletion and rootkits
One of the most worrying features of VoidLink is its adaptive stealth deletion. Upon startup, the software scans for installed security tools and detection systems, assesses the risk, and adjusts its tactics to remain invisible.
Depending on the Linux kernel version, VoidLink installs different rootkits:
- Below version 4.0: Using LD_PRELOAD techniques
- Version 5.5 and above: eBPF -based rootkits
- Version 4.0 and above: Loading kernel modules that hide processes, files, network sockets, and the rootkit modules themselves
These techniques ensure that malware activities remain hidden from system administrators and security tools.
See also: SHADOW#REACTOR: New campaign distributes Remcos RAT
Self-deletion and code modification
VoidLink incorporates self-deleting mechanisms, removing all traces of itself in case of detection or analysis attempt. In addition, its code is self-modifying, decrypting protected areas at runtime and re-encrypting them when not in use. This allows for hiding from memory scanners and continuous monitoring of system integrity.
The combined use of adaptive stealth deletion, rootkits, and self-modifying code makes VoidLink one of the most advanced cyber espionage tools for Linux clouds.

Safety precautions and suggestions
The researchers recommend close monitoring of Linux running in the cloud, especially those hosting sensitive services or development data. Identifying process anomalies and unusual network patterns is critical.
See also: ValleyRAT_S2 attacks organizations to install malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, implementing multi-factor authentication, limited administrator access , and regularly updating systems can reduce the risk of successful exploitation by frameworks like VoidLink.
VoidLink highlights the increasing evolution of cloud attacks, where attackers are no longer just targeting endpoints but entire infrastructures in an adaptive and sophisticated manner. Monitoring and regularly reinforcing cloud security is now more critical than ever.
