Voidshadow: A Modular Cross-Platform Implant Framework

    Date: 09/07/2026

    Severity: Medium

    Summary

    VoidShadow is a modular, cross-platform post-exploitation framework targeting both Windows and Linux systems, providing attackers with full remote control and credential theft capabilities. It uses layered userland and kernel-mode rootkits for stealth and persistence, while its C2 traffic is sent over TLS and disguised as legitimate Microsoft Graph, WordPress, and Google Cloud traffic. 

    Indicators of Compromise (IOC) List 

    Domains/URLs

    aliqopen.com

    cloudapi-update.com

    cloudops-api.com

    dai2345.com

    hk-cloudops-api.com

    luoluo6.com

    IP Address

    47.76.221.103

    47.242.255.141

    8.148.241.46

    Hash

    033cdc85aec2ae5016c61134918860c6969761fdf95c55bb0d84c2e9c333c6a4

    06cf0995f4a03f26c4022efee5a4065cb1a67cc8461b1c248ead1341785f4536

    403a66a70d3af89374f762af3b0351a94cd52e74e839fecf6337b1ba0ef5389a

    52c57b0de24ac1f4a7734e610ffa097c4c63a666d3a780e70adc182d4706b10b

    546bf2c3aca9ed9829c22b19b598c4db058313bd66d72cfeddc27a49ca1e27cb

    deaa0a55a944682b27fd57a55b22978c478234eee93015fc0f2f06a4a1eb4e0f

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "aliqopen.com" or siteurl like "aliqopen.com" or url like "aliqopen.com" or domainname like "cloudapi-update.com" or siteurl like "cloudapi-update.com" or url like "cloudapi-update.com" or domainname like "cloudops-api.com" or siteurl like "cloudops-api.com" or url like "cloudops-api.com" or domainname like "dai2345.com" or siteurl like "dai2345.com" or url like "dai2345.com" or domainname like "hk-cloudops-api.com" or siteurl like "hk-cloudops-api.com" or url like "hk-cloudops-api.com" or domainname like "luoluo6.com" or siteurl like "luoluo6.com" or url like "luoluo6.com"

    Detection Query 2 :

    dstipaddress IN ("47.76.221.103","47.242.255.141","8.148.241.46") or srcipaddress IN ("47.76.221.103","47.242.255.141","8.148.241.46")

    Detection Query 3 :

    sha256hash IN ("033cdc85aec2ae5016c61134918860c6969761fdf95c55bb0d84c2e9c333c6a4","06cf0995f4a03f26c4022efee5a4065cb1a67cc8461b1c248ead1341785f4536","403a66a70d3af89374f762af3b0351a94cd52e74e839fecf6337b1ba0ef5389a","52c57b0de24ac1f4a7734e610ffa097c4c63a666d3a780e70adc182d4706b10b","546bf2c3aca9ed9829c22b19b598c4db058313bd66d72cfeddc27a49ca1e27cb","deaa0a55a944682b27fd57a55b22978c478234eee93015fc0f2f06a4a1eb4e0f")

    Reference:    

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-09-04-VoidShadow-framework.txt                                           


    Tags

    MalwareExploitationCredential HarvestingRootkitMicrosoftWordPress

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags