Cybersecuritynews Emergence of VoidLink Rootkit Threatens Linux Systems with Advanced Evasion Techniques
Article Content
- •VoidLink rootkit combines LKMs and eBPF for deep system infiltration.
- •Targets multiple Linux distributions, including CentOS 7 and Ubuntu 22.04.
- •No specific CVEs disclosed yet, but its stealth capabilities indicate a high risk.
The VoidLink rootkit has been identified as a significant threat to Linux systems, utilizing a combination of Loadable Kernel Modules (LKMs) and extended Berkeley Packet Filter (eBPF) programs for stealthy infiltration. First documented by Check Point Research in January 2026, this malware framework targets a wide range of Linux distributions, including CentOS 7 and Ubuntu 22.04, allowing attackers to hide processes and network activity effectively. The rootkit's design enables it to persist across various kernel versions, posing a risk to cloud-native environments. As of now, specific CVEs related to VoidLink have not been disclosed, but its capabilities suggest a high potential for exploitation. Security professionals are advised to monitor their systems closely for signs of compromise. The full scope of the threat remains under investigation, with ongoing assessments of its impact on cloud infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track VoidLink and Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…