s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.voidlink

📛 Threat Title

Malware family: VoidLink

Category: VoidLink First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.voidlink`. Printable name: VoidLink.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.voidlink VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.voidlink

IOC database

Type
domain
Value
elf.voidlink
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.voidlink

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.voidlink

References (1)

Remediations (10)

  • web:blogs.cisco.com

    Explore how VoidLink , a malware framework, targets Kubernetes and AI workloads. Discover why kernel-level runtime security is the new frontline.

  • web:cyberpress.org

    VoidLink malware rewrites the rootkit playbook using server-side kernel compilation and AI-assisted code to enhance stealth and evasion.

  • web:cybersecuritynews.com

    VoidLink , a cloud-native Linux malware , targets AWS, Azure & containers, adapting stealthily for long-term data theft.

  • web:isovalent.com

    Neutralizing the threat: blocking and mitigation It's not enough to just detect Voidlink ; teams have to stop the attack chain before it implants the system. Tetragon supports two main enforcement actions: override (returning an error, e.g., -1) and process termination (SIGKILL). Override blocks the immediate malicious action (as with the name change event we see further below) by disallowing ...

  • web:malpedia.caad.fkie.fraunhofer.de

    VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized environments. It features a plugin-based architecture with dynamically loadable components that provide reconnaissance, credential harvesting, privilege escalation, lateral movement, persistence, and anti-forensic capabilities. The framework demonstrates strong ...

  • web:research.checkpoint.com

    Key takeaways VoidLink is an advanced malware framework made up of custom loaders, implants, rootkits, and modular plugins designed to maintain long-term access to Linux systems. The framework includes multiple cloud-focused capabilities and modules, and is engineered to operate reliably in cloud and container environments over extended periods.

  • web:research.splunk.com

    Why it matters VoidLink represents a significant evolution in Linux malware targeting cloud-native infrastructure. Discovered by Check Point Research in December 2025, this framework showcases advanced capabilities specifically designed for cloud and container environments.

  • web:securityarsenal.com

    Learn how to detect and remediate the VoidLink Linux C2 framework that targets multi-cloud environments using AI-generated code.

  • web:thehackernews.com

    Check Point reveals VoidLink , a China-linked Linux malware built for cloud environments with modular plugins, rootkit features, and adaptive evasion.

  • web:www.sysdig.com

    The Sysdig threat research team analyzes VoidLink , a Linux malware framework using C2-compiled kernel rootkits, eBPF stealth, and adaptive evasion techniques.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.