Red Heron Exploits Gitea N-Day Flaw in Multinational Campaign
Red Heron Exploits Gitea N-Day Flaw in Multinational Campaign 🚀
Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. The activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster. TRU traced a Linux implant, which we track as JITTERLY, to an exposed staging server operated by Red Heron. Discovered on August 4, the server contained exploitation tools, targeting data, command history, stolen repositories, and malware, providing rare visibility into the actor’s operations, from target selection and vulnerability weaponization to post-exploitation activity.
Red Heron weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, within days of public proof-of-concept code appearing on GitHub. The actor developed it into an automated framework capable of registering accounts, exploiting vulnerable servers, stealing repositories, and removing selected traces. Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka.
The staging server also contained JITTERLY, a C++ Linux implant supporting more than 30 post-exploitation commands, including shell execution, file transfer, network tunneling, interactive terminal access, and internal pivoting. Embedded inside it was SIXZUT, a previously undocumented LD_PRELOAD rootkit capable of hiding files, processes, and network connections, preventing the implant from being terminated, and relaunching it if the process is stopped while the binary remains present. We identified no previous public reporting on SIXZUT. TRU assesses with moderate confidence that Red Heron operates within a PRC-linked context, based on Simplified Chinese operational material, its classification of Taiwan as part of China, and targeting aligned with apparent strategic collection priorities. We have not identified sufficient evidence linking Red Heron to a previously tracked threat group.