216.73.216.6

Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

· Published 26/03/2026 11:59 · Modified 27/03/2026 00:10

Export JSON

Essential information

Published
26/03/2026 11:59
Modified
27/03/2026 00:10
Tags
2026-03-26 ai-assisted lkm rootkit stealth voidlink
Related entities
2 observables, 18 techniques (mitre), 1 malware

Description

Elastic Security Labs analyzes , a sophisticated Linux malware framework combining Loadable Kernel Modules (LKMs) and eBPF for persistence. The , developed by a Chinese-speaking threat actor, evolved through four generations, targeting kernels from CentOS 7 to Ubuntu 22.04. employs advanced techniques like delayed initialization, runtime key rotation, and a hybrid -eBPF architecture for comprehensive . Notable features include an ICMP-based covert channel, process protection, and memfd-aware boot loading. Evidence suggests development, lowering the barrier for kernel-level creation. Detection strategies and defensive recommendations are provided to counter this emerging threat.

External references