Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

Reported 26 Mar 2026 by otx · Severity: medium

Elastic Security Labs analyzes VoidLink, a sophisticated Linux malware framework combining Loadable Kernel Modules (LKMs) and eBPF for persistence. The rootkit, developed by a Chinese-speaking threat actor, evolved through four generations, targeting kernels from CentOS 7 to Ubun