[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpGUiJUTj35a2E_XMshwi5O_FZcpazssndCZ9aj76dak":3},{"article":4,"iocs":31,"watch_terms":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":10,"published_at":12,"ingested_at":13,"relevance_score":14,"entities":15,"category_id":16,"category":17,"article_tags":20},"1ef4efc3-fae4-4b25-bb02-873440b2c28e","We investigated an open web directory on a #VoidLink C2 server that reveals new samples and possi...","we-investigated-an-open-web-directory-on-a-voidlink-c2-server-that-reveals-new-s","We investigated an open web directory on a #VoidLink C2 server that reveals new samples and possible overlaps with activity we track as CL-STA-1015. Previous versions of VoidLink have been seen in the wild as early as 2025-12-02. Details at: https:\u002F\u002Ft.co\u002Fj964tXrRdk https:\u002F\u002Ft.co\u002F3ATYlpt2LL","Security researchers discovered an open web directory on a VoidLink C2 server containing new malware samples and revealing possible connections to tracked activity CL-STA-1015. VoidLink malware variants have been observed in the wild since at least early December 2024, indicating ongoing malicious campaign activity.",null,"https:\u002F\u002Fx.com\u002FUnit42_Intel\u002Fstatus\u002F2031445130364780771","2026-03-10T19:00:36+00:00","2026-03-15T15:00:06.415692+00:00",8,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":16,"icon":10,"name":18,"slug":19},"Malware","malware",[21,26],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":27},{"id":28,"icon":10,"name":29,"slug":30},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[32,35],{"type":19,"value":33,"context":34},"VoidLink","C2 malware with samples found on open web directory; active since 2024-12-02",{"type":36,"value":37,"context":38},"mitre_attack","CL-STA-1015","Tracked activity cluster with possible overlap to VoidLink C2 operations",[]]