VoidLink, a cloud-native malware framework disclosed by Check Point Research in December 2025, represents a new class of threat purpose-built for Kubernetes and Linux container environments. It detects cloud providers, adapts to security postures, harvests credentials, and uses fileless persistence to evade user-space security
Table of contents
VoidLink is the signal. The pattern is the story.How we got here: EDR → cloud → identity → workloadsRuntime protection: The lesson VoidLink teachesThe blind spot most CISOs can’t affordThe path forwardSort: