[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fd68hn9FqJS864EF6Pco10SnvF7BxvQ0391q34i5B38A":3},{"article":4,"iocs":32,"watch_terms":36},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":22,"category":23,"article_tags":26},"b83755da-0200-453a-98ce-084d85956e77","The hybrid design is what makes this stand out.\n\nMost Linux rootkits pick one hiding mechanism. V...","the-hybrid-design-is-what-makes-this-stand-out-most-linux-rootkits-pick-one-hidi-28671c","The hybrid design is what makes this stand out.\n\nMost Linux rootkits pick one hiding mechanism. VoidLink uses two:\n• A Loadable Kernel Module (LKM) for deep syscall hooking, process hiding, and a covert ICMP command channel\n• A companion eBPF program handling the one thing the","VoidLink is a sophisticated Linux rootkit that combines a Loadable Kernel Module (LKM) for syscall hooking and process hiding with a companion eBPF program for enhanced evasion capabilities. The dual-mechanism design allows it to maintain persistence while evading detection through multiple concealment layers, including a covert ICMP command channel for command and control.","VoidLink Linux rootkit employs hybrid LKM and eBPF design for evasion.",null,"https:\u002F\u002Fx.com\u002Felasticseclabs\u002Fstatus\u002F2042271323947200679","2026-04-09T16:00:01+00:00","2026-04-09T17:00:13.653411+00:00",8,[17,20],{"name":18,"type":19},"Linux Loadable Kernel Module (LKM)","technology",{"name":21,"type":19},"eBPF (extended Berkeley Packet Filter)","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":22,"icon":11,"name":24,"slug":25},"Malware","malware",[27],{"category":28},{"id":29,"icon":11,"name":30,"slug":31},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[33],{"type":25,"value":34,"context":35},"VoidLink","Linux rootkit using hybrid LKM and eBPF for hiding and C2",[]]