tech
Never-before-seen Linux malware is “far more advanced than typical”
VoidLink includes an unusually broad and advanced array of capabilities.

TL;DR
- VoidLink is a malware framework targeting Linux machines, especially in cloud environments.
- It includes over 30 modules for stealth, reconnaissance, privilege escalation, and lateral movement.
- The framework can detect and adapt to various cloud services like AWS, GCP, and Azure.
- VoidLink offers advanced features such as rootkit functions, anti-analysis techniques, and credential harvesting.
- Its localized interface suggests a Chinese-affiliated origin, and it appears to be under active development.
- Checkpoint researchers discovered VoidLink in malware samples on VirusTotal, with no signs of it being used in the wild yet.