VoidLink eBPF Rootkit Breakdown

You know I’m a sucker for an eBPF breakdown.

Additional IOCs provided by Unit42 Timely Threat Intel

1 Like

This thing is really slick. In addition to the LKM/eBPF components, the C2 is over ICMP, but they were careful to lock it to a 64-byte packet, so you need to be paying really close attention to distinguish this C2 traffic from noise.

The amount of endpoint visibility on Linux systems necessary to catch this exceeds most orgs’ capabilities.