Back to Feed
Threat IntelligenceMar 10, 2026

Unit42-timely-threat-intel/2026-03-10-IOCs-for-VoidLink-activity.txt at main · PaloAltoNetworks/Unit42-timely-threat-intel

Palo Alto Networks Unit 42 discovered an open web directory on a VoidLink C2 server containing new malware samples and revealing possible connections to tracked activity CL-STA-1015. VoidLink samples have been observed in the wild since early December 2025, with detailed indicators of compromise released for defensive purposes.

Summary

Palo Alto Networks Unit 42 discovered an open web directory on a VoidLink C2 server containing new malware samples and revealing possible connections to tracked activity CL-STA-1015. VoidLink samples have been observed in the wild since early December 2025, with detailed indicators of compromise released for defensive purposes.

Indicators of Compromise

  • malware — VoidLink
  • mitre_attack — CL-STA-1015