VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems

A new and technically advanced rootkit called VoidLink has emerged as a serious threat to Linux systems, blending Loadable Kernel Modules (LKMs) with extended Berkeley Packet Filter (eBPF) programs to hide deep inside the operating system’s core. First documented by Check Point Research in January 2026, VoidLink is a cloud-native Linux malware framework written in […]

The post VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: