TheVoidStl is a cybercriminal threat actor associated with the development and sale of the Void Botnet, a commercially packaged malware loader and botnet platform advertised on a Russian-language cybercrime forum in 2026. The actor is also linked to malware tools identified as TheVoidStealer, WallStealer, and Void Miner, and has been associated with the operator alias nikoniko. Void Botnet is notable for combining decentralized and centralized command-and-control models. It uses Ethereum smart contracts for resilient blockchain-based command-and-control while also supporting a direct web-panel mode for lower-latency tasking. This architecture enables operators to switch between stealthier, disruption-resistant control and faster centralized operations. The malware is written in Rust, supports both 32-bit and 64-bit Windows systems, and is positioned as a ready-to-use criminal offering. The platform supports a broad range of post-compromise activity, including distributed denial-of-service operations, credential theft, proxy operations, reverse shell access, PowerShell tasking, and delivery of additional payloads. It also supports in-memory execution of binaries, allowing payloads to be loaded directly into process memory without being written to disk, which improves defense evasion. Additional operational features include persistence via scheduled task creation, self-update, self-delete, host profiling, privilege awareness, and the ability to selectively task victims by geography. These characteristics indicate a mature criminal toolset designed for flexible monetization and sustained access to compromised Windows hosts. The actor's activity is consistent with financially motivated cybercrime rather than espionage. The available evidence supports attribution to a Russian-language cybercriminal ecosystem, but does not establish specific state sponsorship.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.