Download Privacy Needle App

Type to search

Cybersecurity

Red Heron Exploits Gitea Vulnerability in Multi-National Cyber Espionage Campaign

Share

A suspected Chinese threat actor, tracked as Red Heron, has weaponised a critical remote code execution (RCE) vulnerability in the Gitea development platform to conduct a multi-national espionage campaign. The actor is targeting internet-facing Gitea instances to compromise organisations across six countries, including the United States, Taiwan, Canada, Argentina, Qatar, and Sri Lanka.

The campaign involves the exploitation of CVE-2026-60004. Researchers at the Acronis Threat Research Unit (TRU) noted that within days of the vulnerability’s disclosure in July 2026, Red Heron transformed public proof-of-concept code into an automated Python framework, exp_enhanced.py, capable of registering accounts, exploiting servers, and stealing repositories.

Malware and Stealth Techniques

The threat actor has been observed deploying a C++ Linux implant dubbed JITTERLY. This malware supports more than 30 post-exploitation commands, including shell execution, file transfers, network tunnelling, and internal pivoting.

To evade detection, the attackers utilised a previously undocumented LD_PRELOAD rootkit called SIXZUT. This rootkit can patch 15 different Linux functions to hide files, processes, and network connections, and it is designed to relaunch automatically if it is terminated or removed by security software.

Targeting and Attribution

The campaign’s targeting footprint suggests a focus on high-value sectors, including defence, energy, aerospace, telecommunications, government, public safety, and research. In one instance in Taiwan, the actor successfully progressed from a vulnerable Gitea server to gaining root-level administrative access across a three-node Proxmox cluster.

Acronis researchers have assessed with moderate confidence that Red Heron operates within a China-linked context. This attribution is based on the use of Simplified Chinese, the consistent classification of Taiwan as part of China within the actor’s datasets, and a targeting pattern that aligns with Chinese intelligence collection priorities.

The scale of the scanning operation was significant, with Red Heron scanning 1,386 Gitea instances across seven countries and maintaining a specific dataset of 477 Taiwan-based systems. Organisations using Gitea should ensure they have applied all security patches related to CVE-2026-60004 and are monitoring for unauthorised lateral movement within their infrastructure.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.