Security research highlighted a continued shift in attacker tradecraft toward Linux cloud and container environments, with stealth-focused malware increasingly abusing modern kernel capabilities. Elastic Security Labs documented the evolution of Linux rootkits from userland hijacking and LKM implants to newer generations that leverage eBPF and io_uring for stealth and evasion, citing examples including TripleCross, Boopkit, and RingReaper. Separately, reporting on VoidLink described a cloud-native malware framework designed to operate inside Linux workloads, detect whether it is running in major cloud providers and in Docker/Kubernetes, and adapt its behavior to remain persistent while harvesting sensitive material such as cloud metadata and credentials.
Operationally, the same kernel features and observability gaps being leveraged by attackers are also driving defensive tooling improvements. Trail of Bits released mquire, an open-source Linux memory forensics tool intended to reduce dependency on external debug symbols by extracting structure and symbol information directly from memory using BPF Type Format (BTF) and Kallsyms (e.g., /proc/kallsyms-style data), then exposing findings through an interactive SQL query interface. While mquire is not tied to a single named campaign, it is directly relevant to investigating advanced Linux threats (including kernel-level implants and stealthy cloud malware) by enabling more reliable post-compromise analysis of Linux memory dumps across kernel versions.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-12, Elastic Security Labs published a technical analysis of a leaked VoidLink rootkit data dump containing source code, binaries, and deployment scripts. The report detailed a hybrid LKM-and-eBPF design, linked the framework to a Chinese-speaking threat actor, described operational artifacts suggesting real-world deployment, and released detection guidance including a YARA rule.
On March 5, 2026, Elastic Security Labs published a two-part research series describing the evolution of Linux rootkits toward stealthier eBPF- and io_uring-based techniques. The research explained how these methods can evade traditional module-based and syscall-monitoring defenses and offered detection and hardening guidance.
Cisco Talos reported observing an advanced threat actor using VoidLink in real-world campaigns, primarily targeting technology and financial organizations. According to the report, attackers gained initial access through pre-obtained credentials or exploitation of exposed enterprise services.
Trail of Bits released mquire, an open-source Linux memory forensics tool that analyzes memory dumps without external debug symbols by combining kernel-embedded BTF and Kallsyms data. The tool provides an interactive SQL-style interface for investigating processes, files, network artifacts, kernel modules, logs, and hidden-process indicators.
On 2026-01-16, Sysdig Threat Research published an analysis of the VoidLink Linux malware framework, describing a fileless Zig-based loader chain, adaptive deployment via eBPF, LKM, or hybrid rootkits, and server-side compilation of kernel-specific modules by the C2. Sysdig also documented covert control channels including HTTP, prctl-based local control, and an ICMP backdoor, and assessed the malware as likely developed by Chinese-speaking operators.
In January 2026, Check Point analysts reported that leaked VoidLink development artifacts indicated the framework was built by a single developer using ByteDance's TRAE SOLO AI development environment and a spec-driven workflow. The analysis said the operator produced a functional Linux implant by 2025-12-04, showing AI-assisted malware development had become operational rather than theoretical.
In December 2025, Check Point Research disclosed VoidLink as a cloud-native malware framework built from scratch to target Linux cloud and container workloads. The disclosure highlighted its environment-aware execution and theft of secrets such as cloud metadata, API credentials, and Git tokens.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
11 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourceelastic.co
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcewebflow.sysdig.com
Open sourceinfosec.pub
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.