[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fatET9f7MHU0ZIbf5giK4Fsjg2zZR3exhQvQiUvT_O8o":3},{"article":4,"iocs":42,"watch_terms":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":22,"category":23,"article_tags":26},"8b2c509b-14ef-484f-8439-f2840f60b00b","Here's the clever part defenders need to understand.\n\nnetstat and ss query the kernel through com...","here-s-the-clever-part-defenders-need-to-understand-netstat-and-ss-query-the-ker-3ddf80","Here's the clever part defenders need to understand.\n\nnetstat and ss query the kernel through completely different interfaces. A rootkit that defeats netstat often fails against ss and most do.\n\nVoidLink's eBPF component solves this by \"swallowing\" Netlink messages. Rather than","VoidLink is a sophisticated rootkit that leverages eBPF (extended Berkeley Packet Filter) to intercept and suppress Netlink messages, effectively hiding malicious network activity from both netstat and ss—tools that query the kernel through different interfaces. This dual-interface evasion technique represents an advancement in rootkit design that defeats common defensive detection mechanisms.","VoidLink rootkit uses eBPF to evade detection by neutralizing netstat and ss forensic tools.",null,"https:\u002F\u002Fx.com\u002Felasticseclabs\u002Fstatus\u002F2042271341278052677","2026-04-09T16:00:05+00:00","2026-04-09T17:00:13.653411+00:00",7,[17,20],{"name":18,"type":19},"eBPF","technology",{"name":21,"type":19},"Netlink","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":22,"icon":11,"name":24,"slug":25},"Malware","malware",[27,32,37],{"category":28},{"id":29,"icon":11,"name":30,"slug":31},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[43],{"type":25,"value":44,"context":45},"VoidLink","eBPF-based rootkit with Netlink message suppression capability for network activity concealment",[]]