Red Heron Exploits Gitea Vulnerability in Multi-National Cyber Espionage Campaign
Share
A suspected Chinese threat actor, tracked as Red Heron, has weaponised a critical remote code execution (RCE) vulnerability in the Gitea development platform to conduct a multi-national espionage campaign. The actor is targeting internet-facing Gitea instances to compromise organisations across six countries, including the United States, Taiwan, Canada, Argentina, Qatar, and Sri Lanka.
The campaign involves the exploitation of CVE-2026-60004. Researchers at the Acronis Threat Research Unit (TRU) noted that within days of the vulnerability’s disclosure in July 2026, Red Heron transformed public proof-of-concept code into an automated Python framework, exp_enhanced.py, capable of registering accounts, exploiting servers, and stealing repositories.
Malware and Stealth Techniques
The threat actor has been observed deploying a C++ Linux implant dubbed JITTERLY. This malware supports more than 30 post-exploitation commands, including shell execution, file transfers, network tunnelling, and internal pivoting.
To evade detection, the attackers utilised a previously undocumented LD_PRELOAD rootkit called SIXZUT. This rootkit can patch 15 different Linux functions to hide files, processes, and network connections, and it is designed to relaunch automatically if it is terminated or removed by security software.
Targeting and Attribution
The campaign’s targeting footprint suggests a focus on high-value sectors, including defence, energy, aerospace, telecommunications, government, public safety, and research. In one instance in Taiwan, the actor successfully progressed from a vulnerable Gitea server to gaining root-level administrative access across a three-node Proxmox cluster.
Acronis researchers have assessed with moderate confidence that Red Heron operates within a China-linked context. This attribution is based on the use of Simplified Chinese, the consistent classification of Taiwan as part of China within the actor’s datasets, and a targeting pattern that aligns with Chinese intelligence collection priorities.
The scale of the scanning operation was significant, with Red Heron scanning 1,386 Gitea instances across seven countries and maintaining a specific dataset of 477 Taiwan-based systems. Organisations using Gitea should ensure they have applied all security patches related to CVE-2026-60004 and are monitoring for unauthorised lateral movement within their infrastructure.




Leave a Reply