top of page
perceptive_background_267k.jpg

Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

Published:

26 maart 2026 om 00:00:00

Alert date:

25 maart 2026 om 19:06:05

Source:

elastic.co

Click to open the original link from this advisory

Operating Systems, Ransomware & Malware

Elastic Security Labs provides technical analysis of VoidLink, a sophisticated Linux malware framework that combines traditional Loadable Kernel Modules (LKM) with eBPF technology to maintain persistence on compromised systems. The rootkit framework represents an advanced threat that operates at the kernel level, making it particularly dangerous for Linux environments. The analysis covers the technical implementation details of how VoidLink achieves persistence through dual mechanisms of LKM and eBPF. This represents a concerning evolution in Linux-targeted malware capabilities, combining traditional rootkit techniques with modern eBPF technology.

Technical details

Mitigation steps:

Affected products:

Linux

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page