Never-before-seen Linux malware is “far more advanced than typical”
By Dan Goodin
January 13, 2026
| Notes |
|---|
| Linux malware |
| VoidLink |
| source code |
| modular malware |
| privilege escalation |
| lateral movement |
| reconnaissance |
| AWS, GCP, Azure, Alibaba, Tencent, DigitalOcean, Vultr |
| metadata |
| API |
| Windows malware more common than Linux |
| Check Point https://research.checkpoint.com/2026/voidlink-the-cloud-native-malware-framework/ |
| https://blog.checkpoint.com/research/voidlink-the-cloud-native-malware-framework-weaponizing-linux-infrastructure/ |
| threat actor |
| China |
| symbols, comments in source code suggest VoidLink is still under development |
| no signs it has been used in the wild |
| VirusTotal |
| staged malware |
| loader |
| cloud-first tradecraft |
| Kubernetes |
| Docker |
| hypervisor enumeration |
| malware checking for security software |
| command and control |
| rootkit |
| enumeration of hardening settings |
| post-exploitation framework |
| SSH key harvesting |
| credential harvester |
| cookie theft |
| user and group enumeration |
| git credentials |
| system keyring |