The VoidLink Evolution: AI-Generated Stealth Rootkit Targeting the Linux Kernel
In January 2026, researchers at Check Point Research published what may be the first clearly documented case of advanced AI-generated malware at scale: VoidLink.

New VoidLink Rootkit: A Cloud-Native, Modular Linux Framework Built for Stealth
In January 2026, researchers at Check Point Research published what may be the first clearly documented case of advanced AI-generated malware at scale: VoidLink.
This is not script-kiddie automation.
This is not recycled open-source tooling.
VoidLink is a modular Linux rootkit framework architected, specified, and largely implemented using AI that reached operational maturity in under a week.
For security teams, this marks a turning point.
The Beginning of the AI-Engineered Malware Era
According to the findings, VoidLink stands apart because:
It was developed using Spec Driven Development (SDD)
The developer generated structured sprint plans across three internal “teams”
The project included coding standards, architecture specs, and milestone tracking
The malware reached a functional implant exceeding 88,000 lines of code within a week
Development artifacts exposed clear AI-generated planning and documentation
Previous AI-linked malware cases (e.g., experimentation seen in low-skill campaigns like FunkSec) primarily mirrored existing open-source projects.
VoidLink is different.
It demonstrates how a single capable operator, augmented by AI, can replicate the output of a multi-team engineering organization.
Technical Architecture: A Modular, Cloud-Aware Rootkit Framework
VoidLink is engineered as a structured, multi-layer platform:
Core Capabilities
eBPF-based stealth modules
LKM (Loadable Kernel Module) rootkit components
Dynamic payload loading
Cloud environment enumeration
Container post-exploitation modules
Multi-stage ELF loaders (e.g.,
stage1.bin)
Development Stack (as observed in leaked documentation)
Core Team (Zig)
Arsenal Team (C)
Backend Team (Go)
The planning documentation included:
Sprint schedules (20+ week roadmap)
Coding standards
Protocol definitions
Test reports
Deployment guides
Architecture assessments
Yet real-world telemetry showed rapid capability growth inconsistent with a long sprint cycle, confirming AI-assisted acceleration.
Infrastructure Mapping: VoidLink Command & Control

Our threat intelligence reconstruction shows VoidLink leveraging cloud-hosted infrastructure to mask C2 activity.
Primary Observed Node
IPv4: 8.149.128.10
Network Range: 8.149.0.0/16
ASN: 37963
Autonomous System: Hangzhou Alibaba Advertising Co., Ltd.
RIR: APNIC
Country: CN
TLS JARM Fingerprint: 3fd3fd20d00000021c43d43d00043d204204071741c36579e355f830d285a5
Passive DNS Associations
hd-test-app.ee4m.com.cn
hd-test-gateway.ee4m.com.cn
VirusTotal Detection
17 / 93 engines (partial detection)
Cloud-hosted infrastructure allows malicious traffic to blend into legitimate enterprise environments, especially in hybrid and containerized ecosystems.
Observed Malware Samples Communicating with Infrastructure
| File Name | Type | Detection |
|---|---|---|
| su4da2x.exe | ELF | 36/65 |
| stage1.bin | ELF | 22/51 |
| rxx9pnz.exe | ELF | 38/65 |
| pb9e7.exe | ELF | 34/62 |
| Multiple Win32 EXE/DLL loaders | PE | Up to 53/71 |
This hybrid Windows-to-Linux staging strategy suggests:
Initial foothold via Windows
Lateral movement
Linux workload compromise (servers, containers, cloud nodes)
Why VoidLink Is Dangerous
VoidLink combines:
Kernel-level stealth (eBPF + LKM)
Modular plugin architecture
Cloud-aware targeting
AI-accelerated development cycles
Structured testing and sprint-based execution
Infrastructure resilience via cloud providers
This normalizes high-complexity attacks that previously required nation-state-level resources.
Now, one skilled individual with AI assistance can achieve similar scale.
Our Approach
We focus on ecosystem-level visibility:
1️⃣ Entry & Loader Detection
2️⃣ Cloud C2 Attribution
3️⃣ Kernel & Runtime Detection
4️⃣ Attack Surface Mapping
We don’t just block malware we map the ecosystem.
Indicators of Compromise (IOCs)
Block immediately at firewall, EDR, and SIEM correlation layers.
| IOC Type | Value |
|---|---|
| IPv4 | 8.149.128.10 |
| MD5 | 17dd7ee893698205c715eeff87496b37 |
| MD5 | 286bafae756d2bfe49784410a665897a |
| MD5 | 2c1d348131c4e3e1cb00002f226bad7e |
| MD5 | 4d8671ffc41252bc189b62699cb8cf90 |
| MD5 | 86b72ac9562623ccfa4815f7fa89b2cd |
| SHA1 | 3355f84f97e06a74586fdb170d023ebc7545fa1a |
| SHA1 | 5ffe44b04c0c47c83c1cd694b28c432fcde5867d |
| SHA1 | 64c21741b1787fd811352370d15c02d4972fa975 |
| SHA1 | 6e18b212fb7bda2144a56303e72b1c54f6fdd473 |
| SHA1 | 9cdbc16912dcf188a0f0765ac21777b23b4b2bea |
| SHA256 | 05eac3663d47a29da0d32f67e10d161f831138e10958dcd88b9dc97038948f69 |
| SHA256 | 13025f83ee515b299632d267f94b37c71115b22447a0425ac7baed4bf60b95cd |
| SHA256 | 143274080851cbc095d286d6cc847e5e0aa8aab98bb1501efbf33e4c08e5f345 |
| SHA256 | 15cb93d38b0a4bd931434a501d8308739326ce482da5158eb657b0af0fa7ba49 |
| SHA256 | 4c4201cc1278da615bacf48deef461bf26c343f8cbb2d8596788b41829a39f3f |
| SHA256 | 70aa5b3516d331e9d1876f3b8994fc8c18e2b1b9f15096e6c790de8cdadb3fc9 |
| SHA256 | a12a9eb2e5efe9a64fdf76803ac6be78e780e8a5ed35aca5369b11e2f63af998 |
| SHA256 | f208cebec4f48c853fc8e8e29040cfbe60ce2b5fa29056d67654089335c21efd |
The Strategic Shift
VoidLink is not just malware.
It is proof that:
AI reduces development time from months to days
Engineering rigor can now be automated
Complex offensive frameworks are becoming democratized
If your organization operates:
Linux servers
Kubernetes clusters
Hybrid cloud environments
Containerized workloads
You are in scope.
How We Help
✔ AI-era threat hunting
✔ Cloud-native rootkit detection
✔ Infrastructure ecosystem mapping
✔ Kernel integrity monitoring
✔ Rapid incident response
We help you detect not just files but frameworks.



