Check Point Research reported a newly identified, highly modular Linux malware framework dubbed VoidLink, designed for long-term, stealthy control of Linux servers and containerized infrastructure. The framework is described as “cloud-first,” with a professional operator ecosystem that includes a web-based management dashboard and a custom plugin architecture (reported as inspired by Cobalt Strike’s BOF model) that allows capabilities to be added or removed as campaign objectives change. Reporting indicates VoidLink ships with 30+ modules/plugins spanning reconnaissance, credential theft, privilege escalation, lateral movement, and anti-forensics (including log wiping), and it can adapt its behavior based on the environment to reduce detection risk.
VoidLink is positioned as a direct threat to enterprise cloud workloads, with functionality to identify whether an infected host is running in major public cloud providers by querying instance metadata via provider APIs (including AWS, Azure, GCP, Alibaba Cloud, and Tencent Cloud, with indications of planned expansion to additional providers). Both accounts emphasize that the breadth and engineering quality are atypical for Linux malware and align more with “professional” threat actor tradecraft, reflecting increased attacker focus on Linux servers, Kubernetes clusters, and Docker/containerized environments that underpin modern enterprise deployments.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Alongside its reporting, Check Point provided indicators of compromise and urged defenders to harden Linux cloud and container deployments against the emerging threat. The guidance emphasized risks to cloud infrastructure, Kubernetes, Docker, and DevOps-focused environments.
Check Point publicly reported VoidLink as a highly modular, cloud-aware Linux malware framework with more than 30 modules, adaptive stealth, credential theft, and rootkit capabilities. The researchers said the tooling appeared unusually advanced for Linux malware, suggested possible China-affiliated development indicators, and noted they had not observed real-world infections at the time of reporting.
Check Point Research found a small cluster of previously unseen samples of a new Linux malware framework later named VoidLink. The samples were discovered in December 2025 and appeared to target Linux cloud and container environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcescworld.com
Open sourcesecurityonline.info
Open sourcedarkreading.com
Open sourcecsoonline.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.