UAT-9921 (VoidLink Operator) is a China-nexus threat actor known for AI-enhanced modular framework and eBPF rootkit deployment.
Analyst brief
UAT-9921 (VoidLink Operator) is a China-nexus threat actor active since 2019. They primarily target the Technology and Financial sectors, along with Linux-based IoT and Critical Infrastructure systems. Their key TTPs include exploiting Java serialization vulnerabilities (Apache Dubbo) for initial access, deploying a modular 'VoidLink' framework developed with AI-enabled IDEs, using P2P mesh networking for C2 communication, and leveraging eBPF rootkits for advanced persistence. Defenders should focus on detecting anomalies in Apache Dubbo traffic, investigating unusual Linux kernel modules (especially eBPF), and monitoring for abnormal C2 communication patterns over P2P mesh networks.
UAT-9921
VoidLink Operator
unknown
UAT-9921 is a China-nexus threat actor active since 2019, tracked by Cisco Talos. In 2026, they were observed deploying 'VoidLink', a sophisticated modular framework primarily targeting Linux systems (IoT, Critical Infrastructure). Unique characteristics include the use of AI-enabled IDEs for rapid development (ZigLang implant, GoLang backend), P2P mesh networking for C2, and advanced persistence via eBPF rootkits. They target Technology and Financial sectors exploiting Java serialization vulnerabilities (Apache Dubbo).