VMTech
Discuss a project

Red Heron Targets Gitea Servers in Multi-Country Intrusion Campaign

Red Heron Targets Gitea Servers in Multi-Country Intrusion Campaign

Gitea vulnerability used against 13 organisations

A China-linked threat actor tracked as Red Heron exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to compromise 13 organisations in six countries. Acronis Threat Research Unit attributed the activity to a campaign against internet-facing Gitea instances, affecting four organisations in Taiwan and four in the United States, as well as two in Canada and one each in Argentina, Qatar and Sri Lanka.

The actor scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems. Acronis assessed the activity as operating in a China-linked context with moderate confidence, citing Simplified Chinese labels, treatment of Taiwan as part of China and a targeting pattern aligned with China’s intelligence-collection priorities.

Victims spanned defense, elections, energy, aerospace, telecommunications, government, public safety and research. The campaign moved beyond source-code theft to persistent access, credential collection and lateral movement. In one Taiwanese environment, Red Heron advanced from a vulnerable Gitea server to root-level administration across a three-node Proxmox cluster.

Public exploit code became an automated framework

Red Heron began adapting public proof-of-concept code into an automated Python framework named exp_enhanced.py on July 29, 2026. The framework could register accounts, exploit vulnerable servers, steal repositories and remove selected traces. The speed of that transition followed the vulnerability’s disclosure in July 2026.

Acronis said the attacker also used the same staging infrastructure against 18 Joomla-based websites in 10 countries before cloning the exploit for CVE-2026-60004. Its observed activity included extensive enumeration of an Argentine quantitative trading firm and infrastructure mapping at a Canadian renewable energy company.

In Taiwan, the group exfiltrated hundreds of repositories from an industrial automation company. The material included code related to a SCADA/HMI tool, IoT platform integrations, a network sniffer, server configurations, a surveillance and monitoring product, and internal business applications. Data taken from a Qatar-based target included a learning management platform, an AI chatbot, workflow automation tools and WordPress plugins.

Linux implant and rootkit support persistence

Analysis of an attributed staging server identified a C++ Linux implant called JITTERLY. It supports more than 30 post-exploitation commands, including shell execution, file transfer, process termination, network tunnelling, interactive terminal access and internal pivoting. A researcher known as dmpdump documented overlaps between JITTERLY and the AdaptixC2 agent in July 2026.

The implant also contained an undocumented LD_PRELOAD rootkit named SIXZUT. It patches 15 Linux functions to conceal files, processes and network connections, and can relaunch when it is terminated or removed. That combination is designed to hinder detection and removal after initial access.

For businesses operating self-hosted development platforms, the incident makes exposed-instance inventories, rapid vulnerability remediation and review of repository secrets operational priorities. Teams should also investigate unusual account registrations, repository access, administrative activity and signs of persistence on Linux hosts connected to development infrastructure.

#cybersecurity#gitea#vulnerability#threatintel
Open analytics
On the site 1 views
min read 4 14.09.2026
Instagram

Red Heron Targets Gitea Servers in Multi-Country Intrusion Campaign

Open the post on Instagram ↗