tech

Never-before-seen Linux malware is “far more advanced than typical”

VoidLink includes an unusually broad and advanced array of capabilities.

Never-before-seen Linux malware is “far more advanced than typical”

TL;DR

  • VoidLink is a malware framework targeting Linux machines, especially in cloud environments.
  • It includes over 30 modules for stealth, reconnaissance, privilege escalation, and lateral movement.
  • The framework can detect and adapt to various cloud services like AWS, GCP, and Azure.
  • VoidLink offers advanced features such as rootkit functions, anti-analysis techniques, and credential harvesting.
  • Its localized interface suggests a Chinese-affiliated origin, and it appears to be under active development.
  • Checkpoint researchers discovered VoidLink in malware samples on VirusTotal, with no signs of it being used in the wild yet.