A single source IP, 45.92.1[.]231 (AS210558 - 1337 Services GmbH, Lelystad, NL), spent four days working an internet-facing Docker Engine API on TCP/2375. The actor moved from version probing on 2026-05-24 to interactive container-escape attempts on 2026-05-25, then came back on…
VoidLink
3 posts
- 46 minSelf-Blocking Docker API Abuse Delivers the VoidLink DDoS-for-Hire Botnet
Understanding Current Threats to Kubernetes Environments Threat actors are increasingly targeting Kubernetes environments by exploiting vulnerabilities like React2Shell and misconfigurations to steal service account tokens. These stolen identities are then used to escalate privileges and move laterally into backend cloud infrastructure, leading to severe impacts such as cryptocurrency theft.
Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework VoidLink is a cloud-native Linux malware framework that employs a hybrid Loadable Kernel Module (LKM) and eBPF architecture to achieve deep system concealment. It features advanced evasion techniques such as delayed initialization, an ICMP covert command channel, and eBPF-driven manipulation of Netlink sockets to hide network connections from diagnostic tools. Analysis indicates the framework was developed iteratively using AI-assisted workflows, highlighting a growing trend of LLM-facilitated malware creation.