VOID Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 30, 2025
Last Seen
May 20, 2026

VOID is a malware family promoted by threat actors as an 'AV Killer' with claimed kernel-level capabilities.

Overview

VOID is a malware family promoted by threat actors as an 'AV Killer' with claimed kernel-level capabilities. The attackers assert that VOID can operate at the kernel level to disable or evading antivirus/EDR protections, indicating a shift toward rootkit-like threats that leverage privileged system access. This makes VOID significant as a potential high-skew stealth threat capable of undermining endpoint defenses.

Related Threat Clusters

  • Void Botnet Exploits Ethereum for Command-and-Control Operations

    The Void Botnet, discovered in March 2026, utilizes Ethereum smart contracts to create a resilient command-and-control (C2) infrastructure that is difficult to disrupt. This botnet has emerged on Russian-language…

    2 articles · Updated May 20, 2026
  • Crypt4You Advertises VOID KILLER Malware on Dark Web

    The threat actor Crypt4You has been promoting a new malware tool called VOID KILLER on underground forums. This software functions as a kernel-level antivirus and endpoint detection response (EDR) process killer,…

    2 articles · Updated December 30, 2025

Recent Intelligence Reports

  • Void Botnet Leverages Ethereum for Resilient C2 — Gbhackers · May 20, 2026
  • Hackers Promote “VOID” AV Killer Claiming Kernel — Gbhackers · December 30, 2025

CVSS v3.1 Breakdown