HomeSecurityVoidLink: New malware framework targets Linux systems

VoidLink: New malware framework targets Linux systems

A new cloud-focused malware framework, dubbed VoidLink, has emerged and is causing concern in the cybersecurity community. VoidLink targets Linux systems in cloud environments and stands out for its advanced detection evasion and self-deletion capabilities, making it particularly difficult to detect and analyze.

VoidLink malware framework Linux

Built for Cloud: Targeting AWS, GCP, Azure and beyond

VoidLink is written in the Zig and is designed to recognize major cloud environments, such as AWS, GCP, Azure, Alibaba, and Tencent, and adapt its behavior depending on the platform.

Additionally, it can detect whether it is running inside Kubernetes or Docker containers, allowing attackers to optimize the attack and remain undetected. According to Check Point, the first samples of VoidLink were detected in December 2025 and appear to come from a Chinese development environment, suggesting that the framework is still in development.

See also: What lessons did we learn from the 2025 cyberattacks and the use of AI?

VoidLink functionality: More than 37 plugins

VoidLink comes with over 37 plugins, organized into categories such as identification, credential harvesting, lateral movement, and persistence. These plugins are loaded into memory at runtime and allow attackers to gain access to sensitive data such as cloud credentials and Git systems.

Credential harvesting enables attackers to gain access to critical development infrastructure and cloud system secrets, paving the way for espionage or supply chain attacks.

VoidLink: New malware framework targets Linux systems

Adaptive stealth deletion and rootkits

One of the most worrying features of VoidLink is its adaptive stealth deletion. Upon startup, the software scans for installed security tools and detection systems, assesses the risk, and adjusts its tactics to remain invisible.

Depending on the Linux kernel version, VoidLink installs different rootkits:

  • Below version 4.0: Using LD_PRELOAD techniques
  • Version 5.5 and above: eBPF -based rootkits
  • Version 4.0 and above: Loading kernel modules that hide processes, files, network sockets, and the rootkit modules themselves

These techniques ensure that malware activities remain hidden from system administrators and security tools.

See also: SHADOW#REACTOR: New campaign distributes Remcos RAT

Self-deletion and code modification

VoidLink incorporates self-deleting mechanisms, removing all traces of itself in case of detection or analysis attempt. In addition, its code is self-modifying, decrypting protected areas at runtime and re-encrypting them when not in use. This allows for hiding from memory scanners and continuous monitoring of system integrity.

The combined use of adaptive stealth deletion, rootkits, and self-modifying code makes VoidLink one of the most advanced cyber espionage tools for Linux clouds.

VoidLink: New malware framework targets Linux systems

Safety precautions and suggestions

The researchers recommend close monitoring of Linux running in the cloud, especially those hosting sensitive services or development data. Identifying process anomalies and unusual network patterns is critical.

See also: ValleyRAT_S2 attacks organizations to install malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, implementing multi-factor authentication, limited administrator access , and regularly updating systems can reduce the risk of successful exploitation by frameworks like VoidLink.

VoidLink highlights the increasing evolution of cloud attacks, where attackers are no longer just targeting endpoints but entire infrastructures in an adaptive and sophisticated manner. Monitoring and regularly reinforcing cloud security is now more critical than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS