VoidLink Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
31
occurrences
First Seen
January 13, 2026
Last Seen
May 1, 2026

VoidLink is a malware family tracked across 12 threat clusters and 31 intelligence report mentions on ThreatCluster. First observed January 13, 2026; most recent activity May 1, 2026.

Related Threat Clusters

  • Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros

    A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…

    227 articles · Updated April 30, 2026
  • VoidLink Malware Framework Signals AI-Driven Cyber Threat Evolution

    The VoidLink malware framework, discovered in early 2026, represents a significant advancement in AI-assisted malware development, transitioning from theoretical discussions to a fully operational threat. Built by a…

    3 articles · Updated March 30, 2026
  • Emergence of VoidLink Rootkit Threatens Linux Systems with Advanced Evasion Techniques

    The VoidLink rootkit has been identified as a significant threat to Linux systems, utilizing a combination of Loadable Kernel Modules (LKMs) and extended Berkeley Packet Filter (eBPF) programs for stealthy infiltration.…

    2 articles · Updated March 26, 2026
  • VoidLink Malware Targets Linux Cloud Environments with Advanced Techniques

    A new malware framework named VoidLink has emerged, specifically targeting Linux systems in cloud environments. It utilizes advanced evasion techniques and self-deletion capabilities, and is written in the Zig…

    18 articles · Updated January 13, 2026
  • VoidLink: AI-Generated Linux Malware Framework Emerges

    VoidLink is a newly discovered Linux malware framework that targets cloud environments, featuring 37 plugins and advanced capabilities. It is believed to have been developed by a single individual using artificial…

    13 articles · Updated January 20, 2026
  • VoidLink Malware Targets Cloud and Enterprise Systems

    VoidLink is a Linux-based command-and-control framework identified for long-term intrusions in cloud and enterprise environments. The malware is designed for credential theft, data exfiltration, and stealthy persistence…

    8 articles · Updated February 9, 2026
  • VoidLink: The First Fully AI-Driven Malware Framework Emerges

    The emergence of VoidLink marks a significant development in cybersecurity, being the first advanced malware framework almost entirely created by artificial intelligence. This new malware allows sophisticated threat…

    2 articles · Updated January 21, 2026
  • VoidLink: New Cloud-First Malware Framework Discovered

    In December 2025, Check Point Research identified a new malware framework named VoidLink, originating from a Chinese-speaking development environment. The malware consists of Linux samples that appear to be in-progress…

    2 articles · Updated January 13, 2026
  • VoidLink Malware Developed with AI Technology

    VoidLink, a new malware, has been developed using artificial intelligence, allowing it to evolve rapidly. The development process mimicked the work of a full development team, indicating a significant advancement in…

    2 articles · Updated January 25, 2026
  • AI Assistants Exploited as Covert Command-and-Control Channels

    AI assistants like Grok and Microsoft Copilot can be exploited to serve as covert command-and-control (C2) channels for cybercriminals. These platforms can be manipulated to fetch attacker-controlled URLs, allowing…

    11 articles · Updated February 18, 2026

Recent Intelligence Reports

  • ‘Trivial’ exploit can give attackers root access to Linux kernel — Csoonline · May 1, 2026
  • VoidLink Malware Framework Shows that AI — Cybersecuritynews · March 30, 2026
  • AI Threat Landscape Digest January — Research.Checkpoint · March 29, 2026
  • VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems — Cybersecuritynews · March 26, 2026
  • VoidLink Rootkit Leverages eBPF and Kernel Modules to Stealthily Infiltrate Linux Systems — Gbhackers · March 26, 2026
  • AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks — Research.Checkpoint · February 17, 2026
  • VoidLink Framework Enables On — Cybersecuritynews · February 11, 2026
  • VoidLink Framework Introduces On — Gbhackers · February 11, 2026

CVSS v3.1 Breakdown