216.73.217.22

The Cloud-Native Malware Framework

· Published 13/01/2026 13:59 · Modified 13/01/2026 16:31

Export JSON

Essential information

Published
13/01/2026 13:59
Modified
13/01/2026 16:31
Tags
2026-01-13 chinese-affiliated cloud-native framework linux malware plugins rootkit stealth voidlink
Related entities
3 observables, 14 techniques (mitre), 1 malware

Description

is an advanced designed for systems, focusing on cloud and container environments. It includes custom loaders, implants, rootkits, and modular for long-term access. The employs a flexible architecture with a Plugin API inspired by Cobalt Strike. uses multiple security mechanisms, including runtime code encryption and adaptive behavior based on the detected environment. Developed by developers, it demonstrates high technical expertise across multiple programming languages. The includes cloud-focused capabilities, credential harvesting, and various command-and-control channels. While its intended use remains unclear, appears to be positioned for potential commercial use.

External references