Emergence of VoidLink Rootkit Threatens Linux Systems with Advanced Evasion Techniques

Emergence of VoidLink Rootkit Threatens Linux Systems with Advanced Evasion Techniques

First seen 26 Mar 2026, 19:48 UTC GbhackersCybersecuritynews 91% similarity 61.5

Article Content

Browse articles
ThreatCluster

The VoidLink rootkit has been identified as a significant threat to Linux systems, utilizing a combination of Loadable Kernel Modules (LKMs) and extended Berkeley Packet Filter (eBPF) programs for stealthy infiltration. First documented by Check Point Research in January 2026, this malware framework targets a wide range of Linux distributions, including CentOS 7 and Ubuntu 22.04, allowing attackers to hide processes and network activity effectively. The rootkit's design enables it to persist across various kernel versions, posing a risk to cloud-native environments. As of now, specific CVEs related to VoidLink have not been disclosed, but its capabilities suggest a high potential for exploitation. Security professionals are advised to monitor their systems closely for signs of compromise. The full scope of the threat remains under investigation, with ongoing assessments of its impact on cloud infrastructure.

Key Points: • VoidLink rootkit combines LKMs and eBPF for deep system infiltration. • Targets multiple Linux distributions, including CentOS 7 and Ubuntu 22.04. • No specific CVEs disclosed yet, but its stealth capabilities indicate a high risk.

ThreatCluster AI

Timeline

2026-01-01
VoidLink rootkit first documented by Check Point Research
2026-03-26
Articles published detailing VoidLink's capabilities and threat
Recent
Ongoing investigations into VoidLink's impact and mitigation strategies

Community

Browse all →