Skip to content
VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems

VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems

Cybersecuritynews Tushar Subhra Dutta March 26, 2026

A new and technically advanced rootkit called VoidLink has emerged as a serious threat to Linux systems, blending Loadable Kernel Modules (LKMs) with extended Berkeley Packet Filter (eBPF) programs to hide deep inside the operating system’s core. First documented by Check Point Research in January 2026, VoidLink is a cloud-native Linux malware framework written in […]

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (2)