Skip to main content
Mallory
2 malware families

UAT-9921

Also known asUAT-9921

UAT-9921 is a previously unknown threat actor tracked by Cisco Talos (and associated with reporting by Check Point and Ontinue) observed leveraging a modular intrusion framework called VoidLink, primarily targeting organizations in the technology and financial services sectors. Talos assesses the actor’s activity may date back to at least 2019, though VoidLink appears to be a more recent addition; Talos observed multiple VoidLink-related victims from September 2025 through January 2026. Operations described by Talos include compromising servers and installing VoidLink to establish command-and-control (C2), then using the compromised infrastructure to conduct internal and external network scanning. Initial access has been attributed with high confidence to the use of pre-obtained (stolen) credentials and exploitation of Java serialization vulnerabilities for remote code execution, including issues associated with Apache Dubbo. Post-compromise activity noted includes deployment of a SOCKS proxy and use of open-source tooling such as Fscan for internal reconnaissance and lateral movement; Talos also noted broad scanning (including full Class C ranges) suggesting opportunistic behavior beyond the primary targeted sectors. VoidLink is characterized as a Linux-focused, near-production-ready, “enterprise-grade” implant management framework: a Zig-based single-file implant with C plugins and a Go backend, supporting compile-on-demand plugin generation for different Linux targets. Reported capabilities include stealth/anti-analysis and EDR detection/evasion, obfuscation, anti-forensics, mesh peer-to-peer relaying between implants, and cloud/container awareness (e.g., Kubernetes and Docker checks) with potential container privilege escalation and sandbox escape; Talos also referenced advanced Linux options such as eBPF/loadable-kernel-module rootkit-like functionality. The framework includes built-in auditing and role-based access control (e.g., SuperAdmin/Operator/Viewer). Talos assessed UAT-9921 likely has Chinese-language knowledge based on language indicators in the framework. Talos also reported indications (unconfirmed by recovered samples) that a Windows implant/equivalent may exist or be in development, potentially with plugin loading (including via DLL sideloading).

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics21 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.006
Web Services
TA0001
Initial Access
3 techniques
T1078×3
Valid Accounts
T1190
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
1 technique
T1203×2
Exploitation for Client Execution
TA0003
Persistence
1 technique
T1078×3
Valid Accounts
TA0004
Privilege Escalation
2 techniques
T1078×3
Valid Accounts
T1611×3
Escape to Host
TA0005
Stealth
2 techniques
T1014×4
Rootkit
T1078×3
Valid Accounts
TA0006
Credential Access
1 technique
T1552
Unsecured Credentials
T1552.005×2
Cloud Instance Metadata API
TA0007
Discovery
2 techniques
T1046×2
Network Service Discovery
T1518
Software Discovery
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1090.001×2
Internal Proxy
T1090.002
External Proxy
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping15

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.