TF-MAL-elf.voidlink
📛 Threat Title
Malware family: VoidLink
Description
ThreatFox malware family `elf.voidlink`. Printable name: VoidLink.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.voidlink
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.voidlink
IOC database
- Type
- domain
- Value
elf.voidlink- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.voidlink
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.voidlink
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blogs.cisco.com
Explore how VoidLink , a malware framework, targets Kubernetes and AI workloads. Discover why kernel-level runtime security is the new frontline.
-
web:cyberpress.org
VoidLink malware rewrites the rootkit playbook using server-side kernel compilation and AI-assisted code to enhance stealth and evasion.
-
web:cybersecuritynews.com
VoidLink , a cloud-native Linux malware , targets AWS, Azure & containers, adapting stealthily for long-term data theft.
-
web:isovalent.com
Neutralizing the threat: blocking and mitigation It's not enough to just detect Voidlink ; teams have to stop the attack chain before it implants the system. Tetragon supports two main enforcement actions: override (returning an error, e.g., -1) and process termination (SIGKILL). Override blocks the immediate malicious action (as with the name change event we see further below) by disallowing ...
-
web:malpedia.caad.fkie.fraunhofer.de
VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized environments. It features a plugin-based architecture with dynamically loadable components that provide reconnaissance, credential harvesting, privilege escalation, lateral movement, persistence, and anti-forensic capabilities. The framework demonstrates strong ...
-
web:research.checkpoint.com
Key takeaways VoidLink is an advanced malware framework made up of custom loaders, implants, rootkits, and modular plugins designed to maintain long-term access to Linux systems. The framework includes multiple cloud-focused capabilities and modules, and is engineered to operate reliably in cloud and container environments over extended periods.
-
web:research.splunk.com
Why it matters VoidLink represents a significant evolution in Linux malware targeting cloud-native infrastructure. Discovered by Check Point Research in December 2025, this framework showcases advanced capabilities specifically designed for cloud and container environments.
-
web:securityarsenal.com
Learn how to detect and remediate the VoidLink Linux C2 framework that targets multi-cloud environments using AI-generated code.
-
web:thehackernews.com
Check Point reveals VoidLink , a China-linked Linux malware built for cloud environments with modular plugins, rootkit features, and adaptive evasion.
-
web:www.sysdig.com
The Sysdig threat research team analyzes VoidLink , a Linux malware framework using C2-compiled kernel rootkits, eBPF stealth, and adaptive evasion techniques.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.