Alpha Cyber

The VoidLink Evolution: AI-Generated Stealth Rootkit Targeting the Linux Kernel

In January 2026, researchers at Check Point Research published what may be the first clearly documented case of advanced AI-generated malware at scale: VoidLink.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Voidlink Rootkit Cover Photo

In January 2026, researchers at Check Point Research published what may be the first clearly documented case of advanced AI-generated malware at scale: VoidLink.

This is not script-kiddie automation.
This is not recycled open-source tooling.

VoidLink is a modular Linux rootkit framework architected, specified, and largely implemented using AI that reached operational maturity in under a week.

For security teams, this marks a turning point.

The Beginning of the AI-Engineered Malware Era

According to the findings, VoidLink stands apart because:

  • It was developed using Spec Driven Development (SDD)

  • The developer generated structured sprint plans across three internal “teams”

  • The project included coding standards, architecture specs, and milestone tracking

  • The malware reached a functional implant exceeding 88,000 lines of code within a week

  • Development artifacts exposed clear AI-generated planning and documentation

Previous AI-linked malware cases (e.g., experimentation seen in low-skill campaigns like FunkSec) primarily mirrored existing open-source projects.

VoidLink is different.

It demonstrates how a single capable operator, augmented by AI, can replicate the output of a multi-team engineering organization.

Technical Architecture: A Modular, Cloud-Aware Rootkit Framework

VoidLink is engineered as a structured, multi-layer platform:

Core Capabilities

  • eBPF-based stealth modules

  • LKM (Loadable Kernel Module) rootkit components

  • Dynamic payload loading

  • Cloud environment enumeration

  • Container post-exploitation modules

  • Multi-stage ELF loaders (e.g., stage1.bin)

Development Stack (as observed in leaked documentation)

  • Core Team (Zig)

  • Arsenal Team (C)

  • Backend Team (Go)

The planning documentation included:

  • Sprint schedules (20+ week roadmap)

  • Coding standards

  • Protocol definitions

  • Test reports

  • Deployment guides

  • Architecture assessments

Yet real-world telemetry showed rapid capability growth inconsistent with a long sprint cycle, confirming AI-assisted acceleration.

Voidlink Rootkit Graph

Our threat intelligence reconstruction shows VoidLink leveraging cloud-hosted infrastructure to mask C2 activity.

Primary Observed Node

IPv4: 8.149.128.10
Network Range: 8.149.0.0/16
ASN: 37963
Autonomous System: Hangzhou Alibaba Advertising Co., Ltd.
RIR: APNIC
Country: CN

TLS JARM Fingerprint: 3fd3fd20d00000021c43d43d00043d204204071741c36579e355f830d285a5

Passive DNS Associations

  • hd-test-app.ee4m.com.cn

  • hd-test-gateway.ee4m.com.cn

VirusTotal Detection

  • 17 / 93 engines (partial detection)

Cloud-hosted infrastructure allows malicious traffic to blend into legitimate enterprise environments, especially in hybrid and containerized ecosystems.

Observed Malware Samples Communicating with Infrastructure

File NameTypeDetection
su4da2x.exeELF36/65
stage1.binELF22/51
rxx9pnz.exeELF38/65
pb9e7.exeELF34/62
Multiple Win32 EXE/DLL loadersPEUp to 53/71

This hybrid Windows-to-Linux staging strategy suggests:

  1. Initial foothold via Windows

  2. Lateral movement

  3. Linux workload compromise (servers, containers, cloud nodes)

VoidLink combines:

  • Kernel-level stealth (eBPF + LKM)

  • Modular plugin architecture

  • Cloud-aware targeting

  • AI-accelerated development cycles

  • Structured testing and sprint-based execution

  • Infrastructure resilience via cloud providers

This normalizes high-complexity attacks that previously required nation-state-level resources.

Now, one skilled individual with AI assistance can achieve similar scale.

Our Approach

We focus on ecosystem-level visibility:

1️⃣ Entry & Loader Detection
2️⃣ Cloud C2 Attribution
3️⃣ Kernel & Runtime Detection
4️⃣ Attack Surface Mapping

We don’t just block malware we map the ecosystem.

Indicators of Compromise (IOCs)

Block immediately at firewall, EDR, and SIEM correlation layers.

IOC TypeValue
IPv48.149.128.10
MD517dd7ee893698205c715eeff87496b37
MD5286bafae756d2bfe49784410a665897a
MD52c1d348131c4e3e1cb00002f226bad7e
MD54d8671ffc41252bc189b62699cb8cf90
MD586b72ac9562623ccfa4815f7fa89b2cd
SHA13355f84f97e06a74586fdb170d023ebc7545fa1a
SHA15ffe44b04c0c47c83c1cd694b28c432fcde5867d
SHA164c21741b1787fd811352370d15c02d4972fa975
SHA16e18b212fb7bda2144a56303e72b1c54f6fdd473
SHA19cdbc16912dcf188a0f0765ac21777b23b4b2bea
SHA25605eac3663d47a29da0d32f67e10d161f831138e10958dcd88b9dc97038948f69
SHA25613025f83ee515b299632d267f94b37c71115b22447a0425ac7baed4bf60b95cd
SHA256143274080851cbc095d286d6cc847e5e0aa8aab98bb1501efbf33e4c08e5f345
SHA25615cb93d38b0a4bd931434a501d8308739326ce482da5158eb657b0af0fa7ba49
SHA2564c4201cc1278da615bacf48deef461bf26c343f8cbb2d8596788b41829a39f3f
SHA25670aa5b3516d331e9d1876f3b8994fc8c18e2b1b9f15096e6c790de8cdadb3fc9
SHA256a12a9eb2e5efe9a64fdf76803ac6be78e780e8a5ed35aca5369b11e2f63af998
SHA256f208cebec4f48c853fc8e8e29040cfbe60ce2b5fa29056d67654089335c21efd

The Strategic Shift

VoidLink is not just malware.

It is proof that:

  • AI reduces development time from months to days

  • Engineering rigor can now be automated

  • Complex offensive frameworks are becoming democratized

If your organization operates:

  • Linux servers

  • Kubernetes clusters

  • Hybrid cloud environments

  • Containerized workloads

You are in scope.

How We Help

✔ AI-era threat hunting
✔ Cloud-native rootkit detection
✔ Infrastructure ecosystem mapping
✔ Kernel integrity monitoring
✔ Rapid incident response

We help you detect not just files but frameworks.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]