SIXZUT is a Linux LD_PRELOAD rootkit embedded in the JITTERLY post-exploitation implant. It is designed to conceal malicious files, processes, and network connections from Linux monitoring utilities by intercepting multiple libc functions. SIXZUT also protects the JITTERLY implant by interfering with process-termination attempts and can relaunch the implant if its process is stopped while its binary remains available. The rootkit has been associated with Red Heron, a suspected Chinese-speaking, PRC-linked threat actor that compromised internet-facing Gitea servers and conducted source-code theft, credential collection, persistence, and lateral movement against organizations in multiple countries and strategic sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Red Heron weaponized CVE-2026-60004, a critical remote-code-execution vulnerability in Gitea (CVSS v3.1: 9.8) affecting versions 1.17 through 1.27.0. The diffpatch endpoint permits placement of a malicious Git hook through double patch submission. | SIXZUT est un rootkit LD_PRELOAD inédit embarqué dans JITTERLY, qui se dépose sous le nom libglthread.so.2 et masque fichiers, processus et connexions réseau.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SIXZUT est un rootkit LD_PRELOAD inédit embarqué dans JITTERLY, qui se dépose sous le nom libglthread.so.2 et masque fichiers, processus et connexions réseau.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
SIXZUT est un rootkit LD_PRELOAD inédit embarqué dans JITTERLY, qui masque fichiers, processus et connexions réseau.
JITTERLY contient un rootkit embarqué chiffré en AES-128-CTR.
The rootkit drops a 49 KB ELF shared library to disk under the name libglthread.so.2, disguised to look like a legitimate OpenGL threading library.
JITTERLY se déguise sous le nom de processus configd; SIXZUT se dépose sous libglthread.so.2, imitant une bibliothèque OpenGL légitime.
[The framework was] capable of ... removing selected traces; [SIXZUT can] cover up traces of malicious activity and prevent the malware from being detected and killed.
“SIXZUT ... [was] capable of hiding files, processes, and network connections.”
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rootkit Linux ELF partagé de 49 Ko, déployé par JITTERLY. Il intercepte 15 fonctions libc afin de dissimuler fichiers, processus et connexions réseau, empêche la terminaison de JITTERLY via un hook de kill(), et relance l’implant lorsqu’il est arrêté.
A previously undocumented LD_PRELOAD Linux rootkit embedded in JITTERLY. It hides files, processes, and network connections; protects the implant from termination; and relaunches it when stopped if its binary remains present.
Embedded Linux LD_PRELOAD rootkit used by JITTERLY to hide files, processes, and network connections; resist termination; and relaunch the implant after removal or stoppage.
Embedded Linux LD_PRELOAD rootkit used by JITTERLY to conceal files, processes, and network connections, resist termination, and relaunch the implant after removal or stoppage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.