JITTERLY is a C++ ELF backdoor for Linux that provides a broad post-exploitation command set, including shell command execution, interactive PTY sessions, file upload and download, process termination, port scanning, TCP and SOCKS tunneling, reverse port forwarding, and internal-network pivoting. It communicates with command-and-control infrastructure over raw TCP using MessagePack serialization and AES-128-GCM encryption, and its protocol and command structure are compatible with Adaptix C2 Gopher communications. JITTERLY includes an encrypted embedded LD_PRELOAD rootkit, SIXZUT, which hides files, processes, and network connections; impedes termination attempts against protected processes; and can relaunch the implant when it is stopped. JITTERLY has been linked to the suspected PRC-associated, Chinese-speaking Red Heron threat actor, whose activity targeted internet-facing Gitea systems and organizations in sectors including energy, government, defense, elections, aerospace, telecommunications, and research.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Red Heron weaponized CVE-2026-60004, a critical remote-code-execution vulnerability in Gitea (CVSS v3.1: 9.8) affecting versions 1.17 through 1.27.0. The diffpatch endpoint permits placement of a malicious Git hook through double patch submission. | JITTERLY est un implant ELF C++ supportant plus de 30 commandes post-exploitation, incluant l’exécution de shell, le transfert de fichiers, le tunneling réseau, un terminal PTY interactif et le pivoting interne.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
JITTERLY est un implant ELF C++ supportant plus de 30 commandes post-exploitation, incluant l’exécution de shell, le transfert de fichiers, le tunneling réseau, un terminal PTY interactif et le pivoting interne.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
When Git later performs an index-related action, the malicious hook executes commands with the permissions of the Gitea service account. JITTERLY supports command execution and interactive terminal sessions.
SIXZUT est un rootkit LD_PRELOAD inédit embarqué dans JITTERLY, qui masque fichiers, processus et connexions réseau.
JITTERLY contient un rootkit embarqué chiffré en AES-128-CTR.
The rootkit drops a 49 KB ELF shared library to disk under the name libglthread.so.2, disguised to look like a legitimate OpenGL threading library.
JITTERLY se déguise sous le nom de processus configd; SIXZUT se dépose sous libglthread.so.2, imitant une bibliothèque OpenGL légitime.
The networking stack supports SOCKS/TCP tunneling, reverse port forwarding, pivot relaying, and interactive PTY terminals.
JITTERLY prend en charge le tunneling réseau SOCKS/TCP et le pivoting interne.
JITTERLY communique avec son C2 via TCP brut, avec sérialisation msgpack et chiffrement AES-128-GCM.
JITTERLY supports more than 30 post-exploitation commands, including shell execution, file transfer, network tunneling, interactive terminal access, and internal pivoting.
“JITTERLY ... support[ed] ... network tunneling ... and internal pivoting.”
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Implant Linux ELF en C++ fournissant un accès distant et des capacités post-exploitation. Il communique avec son C2 sur TCP brut, avec sérialisation msgpack et chiffrement AES-128-GCM; il est compatible avec Adaptix C2, se fait passer pour le processus configd, et contient le rootkit SIXZUT embarqué et chiffré.
A C++ Linux post-exploitation implant that provides shell execution, file transfer, network tunneling, interactive terminal access, and internal pivoting. It embeds the SIXZUT rootkit.
Linux backdoor implant that provides remote command execution, file transfer, tunneling, interactive shell access, port scanning, reverse port forwarding, and internal-network pivoting. It uses encrypted messages over raw TCP for command-and-control and embeds the SIXZUT LD_PRELOAD rootkit for concealment and persistence.
Linux backdoor/implant used for remote command execution, file transfer, encrypted raw-TCP C2 communications, tunneling, port scanning, reverse port forwarding, and lateral movement/pivoting. It embeds the SIXZUT LD_PRELOAD rootkit for stealth and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.