Advanced VoidLink Linux malware steals credentials from the cloud

Some people, bless them, still believe that only Windows systems are vulnerable to cybersecurity attacks. Some people still think that Mac and Linux systems are magically immune to cyber threats. Let me introduce them, and you, to VoidLink, an advanced malware framework that can maintain ongoing access to Linux systems, engineered to steal credentials in the cloud and then vanish.

A newly published analysis out of the Check Point Research labs has confirmed that VoidLink, which the researchers said โ€œappears to be built and maintained by Chinese-affiliated developers,โ€ displays a high level of technical expertise and, worryingly, is continuing to evolve.

This modular and highly advance malware framework is, the report stated, comprised of โ€œcustom loaders, implants, rootkits, and modular pluginsโ€ designed to maintain long-term access to Linux systems and comes replete with multiple cloud-focused capabilities.

Not only that, but it is built with OPSEC in mind. That is, operational security, with mechanisms to avoid being detected by OPSEC defences part of the evolution of such malware. VoidLink deploys everything it can muster to throw at such defences: runtime code encryption, self-deletion upon tampering and, Check Point warned, โ€œadaptive behaviour based on the detected environment alongside a range of user-mode and kernel-level rootkit capabilitiesโ€.

โ€œThe ability to adapt to different environments once activated, silently extract data while disguised as normal web activity, and self-delete upon detecting tampering to reduce exposure to forensic investigations,โ€ said Ross Filipek, CISO at Corsica Technologies, โ€œis enough to give the best security teams a migraine.โ€

He went further to warn that โ€œthe prospect of this framework eventually being available for purchase on the cyber black market should make security teams very worriedโ€.

I have to agree. The intention to automate evasion is perhaps the most worrying part of this malware evolution: being able to effectively profile the environment it’s attacking and then select the optimal strategy to operate within it, while remaining undetected. โ€œAugmented by kernel-mode tradecraft and a vast plugin ecosystem,โ€ Check Point said, โ€œVoidLink enables its operators to move through cloud environments and container ecosystems with adaptive stealth.โ€

Linux admins have every right to be concerned, and I would be worried if they were not. Not least as Linux remains an overlooked target for defenders. โ€œThe creation of a framework dedicated to the Linux platform and more specifically, cloud environments, shows that these platforms are a valid target for threat actors,โ€ Check Point concluded.

A chink of good news

The good news in all of this is that the discovery of the framework is not the same as the discovery of an attack campaign.

Indeed, Check Point itself admitted that โ€œit is not clear if the framework is intended to be sold as a legitimate penetration testing tool, as a tool for the criminal underground, or as a dedicated product for a single customer,โ€ at this stage.

But, the fact remains, as Filipek concluded, โ€œaccess to Linux cloud servers could be devastating, as attackers may be able to tamper with large-scale infrastructure and exfiltrate sensitive information and intellectual property while remaining largely undetectedโ€.

For these reasons, I recommend that all cybersecurity professionals take the potential threat very seriously indeed and proactively secure Linux and cloud environments, including container environments, to defend against whatever comes next.

And that means, for all people, non-stop monitoring alongside intrusion detection so as to quickly identify traffic anomalies before VoidLink gets a chance to spread.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.