voidlink-goodin2026

2026-09-25

Never-before-seen Linux malware is “far more advanced than typical”

By Dan Goodin

January 13, 2026

Notes
Linux malware
VoidLink
source code
modular malware
privilege escalation
lateral movement
reconnaissance
AWS, GCP, Azure, Alibaba, Tencent, DigitalOcean, Vultr
metadata
API
Windows malware more common than Linux
Check Point https://research.checkpoint.com/2026/voidlink-the-cloud-native-malware-framework/
https://blog.checkpoint.com/research/voidlink-the-cloud-native-malware-framework-weaponizing-linux-infrastructure/
threat actor
China
symbols, comments in source code suggest VoidLink is still under development
no signs it has been used in the wild
VirusTotal
staged malware
loader
cloud-first tradecraft
Kubernetes
Docker
hypervisor enumeration
malware checking for security software
command and control
rootkit
enumeration of hardening settings
post-exploitation framework
SSH key harvesting
credential harvester
cookie theft
user and group enumeration
git credentials
system keyring

No notes link to this note