216.73.216.233

VoidLink threat analysis: C2-compiled kernel rootkits discovered

· Published 19/01/2026 09:35 · Modified 19/01/2026 09:58

Export JSON

Essential information

Published
19/01/2026 09:35
Modified
19/01/2026 09:58
Tags
2026-01-19 c2 cloud containers ebpf evasion kernel linux rootkit stealth voidlink zig
Related entities
9 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 5 others

Description

The Sysdig Threat Research Team analyzed , a sophisticated malware framework targeting environments. Key findings include the first documented Serverside Compilation, Chinese development with AI assistance, adaptive detection , and use of the programming language. employs a multi-stage loader architecture, fileless execution techniques, and -level mechanisms. It features three control channels, including a covert ICMP channel, and specialized functionality for and container environments. Despite its sophistication, can be detected using runtime monitoring tools. The malware shows indicators of Chinese-speaking developers with significant expertise, likely using AI-assisted development methods.

External references