Skip to main content

New tool voidsyscall : Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

0
Medium
Published: 09/13/2026 (09/13/2026, 14:28:36 UTC)
Source: Reddit Cybersecurity

Description

voidsyscall is a cross-platform implant and command-and-control (C2) framework that operates by issuing direct syscalls on Windows and raw syscalls on Linux, bypassing the Windows API layer entirely. It uses multiple stealthy injection techniques and evasion methods to avoid detection by endpoint detection and response (EDR) tools, including runtime resolution of syscall numbers, unhooking ntdll, and polymorphic code injection. The implant supports encrypted C2 communication over HTTPS, DNS, and ICMP channels using AES-256-GCM encryption. It includes advanced anti-analysis features such as VM, sandbox, and debugger detection, and performs token manipulation and memory encryption to hinder forensic analysis. No official patch or remediation is indicated, and this tool is presented as an offensive implant framework rather than a vulnerability.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/13/2026, 14:46:33 UTC

Technical Analysis

voidsyscall is a sophisticated implant framework that bypasses the Windows API by issuing direct syscalls resolved at runtime from ntdll, avoiding usermode hooks and EDR detection. It supports Windows, Linux, and macOS platforms and uses multiple stealthy injection methods including section mapping, process hollowing, APC queuing, and module stomping. The implant performs extensive anti-analysis checks including VM, sandbox, and debugger detection, and patches AMSI, ETW, and other instrumentation callbacks to evade detection. Communication with C2 servers is encrypted with AES-256-GCM over HTTPS, DNS, and ICMP channels. The implant also includes capabilities for token privilege escalation, memory region hiding, secure file I/O, and registry persistence using only syscalls. It is not a syscall wrapper library but a full implant framework designed for stealth and evasion.

Potential Impact

The implant enables attackers to execute code stealthily on compromised systems across multiple platforms, evade detection by common security tools, escalate privileges, persist via registry modifications, and communicate securely with C2 servers. Its advanced evasion techniques and direct syscall usage make detection and forensic analysis challenging. There is no indication of active exploitation in the wild or a vulnerability being exploited; rather, this is an offensive tool that could be used by threat actors for post-exploitation activities.

Defensive Guidance

No official patch or remediation is available or applicable as this is an offensive implant framework rather than a software vulnerability. Defenders should rely on behavioral detection, network monitoring for anomalous encrypted C2 traffic over HTTPS, DNS, or ICMP, and endpoint protections that can detect direct syscall usage or unusual injection techniques. Awareness of this tool's capabilities can inform threat hunting and incident response efforts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:ttps","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ttps"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa6b74355bf5e2cf5baac79

Added to database: 09/13/2026, 14:46:27 UTC

Last enriched: 09/13/2026, 14:46:33 UTC

Last updated: 09/14/2026, 04:01:25 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses