Cybersecuritynews
VoidLink Framework Emerges as Modular Malware for Linux and Cloud Systems
First seen 12 Feb 2026, 12:40 UTC
•


•85% similarity
•20.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The VoidLink framework has been identified as a new modular malware tool targeting Linux systems and cloud environments. Cisco Talos has linked this framework to the threat actor UAT-9921, which is known for compromising internet-facing servers. Key features of VoidLink include on-demand compilation and modular plugins, indicating a shift towards AI-enabled attack platforms.
ThreatCluster AI
How this analysis works
Timeline
2026-02-11
VoidLink framework publicly exposed by cybersecurity analysts
2026-02-11
Cisco Talos links VoidLink to threat actor UAT-9921
Recent
VoidLink activity observed in the wild