Red Heron Exploits Gitea CVE-2026-60004 in Multinational Campaign, Deploys Linux Rootkit

Summary
Acronis researchers detail Red Heron’s exploitation of vulnerable Gitea servers to steal source code, collect credentials and move into victim networks, alongside analysis of the JITTERLY implant and embedded SIXZUT rootkit.
Key points
- Red Heron weaponized critical Gitea remote code execution flaw CVE-2026-60004 within days of public proof-of-concept code. The flaw affects versions 1.17 through 1.27.0; Gitea patched it in version 1.27.1.
- With open registration enabled, attackers could register an account and exploit the diffpatch endpoint without prior credentials. Red Heron scanned 1,386 Gitea instances across seven countries and compiled a separate list of 477 Taiwan-based systems.
- Acronis documented compromises in Canada, Argentina, Taiwan, the United States and Sri Lanka, including repository theft, credential and secret collection, SSH persistence and lateral movement. One intrusion reached root-level control of a three-node Proxmox cluster.
- The actor’s JITTERLY Linux implant supports more than 30 commands, including file transfer, shell execution, tunneling and network pivoting. It contains SIXZUT, an undocumented LD_PRELOAD rootkit that hides files, processes and network connections and helps restore the implant.
- Acronis assesses with moderate confidence that Red Heron operated in a PRC-linked context, citing Simplified Chinese operational records, target classifications and victimology; researchers found no sufficient evidence linking it to a previously tracked group.
- Acronis recommends upgrading Gitea to 1.27.1 or later, disabling unneeded open registration, investigating for signs of compromise and rotating credentials and secrets exposed in affected repositories. Confirmed compromises should be rebuilt rather than cleaned in place.
Article Details
- Attack Vectors
- Red Heron exploited CVE-2026-60004 in internet-facing Gitea instances. A crafted patch submitted twice forced Git's three-way merge path to write an executable hook into a bare temporary clone, resulting in code execution as the Gitea service account.
- On Gitea instances with open registration, the actor created accounts and repositories to reach the writable diffpatch route without pre-existing credentials.
- The actor used automated exploitation to collect repositories and Gitea data, planted SSH keys and backdoors, and moved from a compromised Taiwanese Gitea environment to root-level access on a three-node Proxmox cluster.
- JITTERLY provided command execution, file transfer and internal-pivoting capabilities. Its embedded SIXZUT rootkit used LD_PRELOAD to conceal artifacts and connections and protect or relaunch the implant.
- The operator also ran a separate campaign against 18 websites, 17 of which were confirmed to run Joomla. The exploited vulnerability and whether its `-shell` option successfully deployed backdoors were not established.
- Defensive Notes
- Upgrade Gitea to version 1.27.1 or later; disable unnecessary open registration, restrict the diffpatch route where unused, and avoid direct internet exposure where authenticated access is practical.
- Review recently created Gitea accounts and repositories, diffpatch requests, and requests to `/api/v1/metrics` with unfamiliar query parameters. Investigate Gitea processes spawning shells, interpreters or curl.
- Inspect `/etc/ld.so.preload`, unauthorized `authorized_keys` entries, and outbound reverse-shell or beacon traffic. Hunt for `libglthread.so.2`, `.ld_aux_cahe` and `/tmp/.X11-unix.lk` using trusted offline, kernel-level or EDR evidence because SIXZUT can hide them from live userland tools.
- If compromise is confirmed, rebuild affected hosts rather than relying on live removal. Assume repositories were taken, inspect them for further secrets, and rotate credentials, tokens and SSH host keys stored in the compromised Gitea instance.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 981666[.]xyz | Parent domain listed with JITTERLY command-and-control infrastructure. |
| DOMAIN | s2[.]981666[.]xyz | JITTERLY command-and-control domain. |
| DOMAIN | xcyoibfhuufz[.]com | Related domain listed among the campaign's network indicators. |
| IPV4 | 72[.]11[.]138[.]109 | Red Heron's staging server. |
| SHA256 | 28b132ad55bd310bb5cf3ddb4ace580529ad735204a48cf388830d9039843d8e | SHA-256 of the SIXZUT rootkit decrypted from JITTERLY. |
| SHA256 | b441f793c87e54cb7e3f7205e25442aa19920d325cb6af41d2afdc8a0b5cf54f | SHA-256 of the JITTERLY implant, listed as agent.elf. |
MITRE ATT&CK
T1014 · RootkitSIXZUT is an LD_PRELOAD rootkit that hides files, processes and network connections and interferes with termination of the implant.T1027 · Obfuscated Files or InformationJITTERLY carries an AES-encrypted SIXZUT rootkit blob, while SIXZUT decrypts sensitive strings at runtime.T1070.004 · File DeletionThe automated exploit framework attempted to remove selected traces from the Gitea database after exploitation.T1098.004 · SSH Authorized KeysThe operator planted SSH keys in a compromised server's authorized_keys file for persistent access.T1110.002 · Password CrackingThe operator used hashcat to crack stolen Gitea database credentials stored as bcrypt hashes.T1190 · Exploit Public-Facing ApplicationRed Heron exploited CVE-2026-60004 on internet-facing Gitea instances to execute code as the Gitea service account.T1213.003 · Code RepositoriesRed Heron's exploitation framework dumped repositories from compromised Gitea servers, and recovered staging-server folders contained stolen source code.T1552.001 · Credentials In FilesThe operator extracted JWT tokens, internal tokens and SSH host keys from Gitea configuration on a compromised company's server.T1573.001 · Symmetric CryptographyJITTERLY encrypts its custom TCP command-and-control messages with per-session AES-128-GCM keys.T1574.006 · Dynamic Linker HijackingSIXZUT writes its shared-library path to `/etc/ld.so.preload`, causing dynamically linked processes to load the rootkit.T1595 · Active ScanningThe actor scanned 1,386 Gitea instances and probed for open registration before prioritizing targets.
CVE
Threat Actors
Malware
Vendors
Products
ForgejoEducation platform (Forgejo)Gitsits in Gitea's diffpatch endpoint. When processing repository patches, the vulnerable code runs git apply --index --recount --cached --binary inside a bare temporary clone and adds the -3 flag to enableGiteaRed Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkitJCE editorfamous overseas education consulting firm based out of India, was confirmed still running a vulnerable JCE editor version (2.9.99) at the time of our analysis. We also observed that the operator targeted a US-based ITJoomlacluster. The same infrastructure was also associated with a separate campaign targeting 18 predominantly Joomla-based websites across 10 countries.Proxmox Virtual Environmentand based on the logs, we think that the naming is quite deliberate, where pve stood for Proxmox Virtual Environment, enum for enumeration, 02 for second attempt. Their first run under the dsaopk handle returnedSynology NASIndustrial automation (Synology NAS)
Tools
Adaptix C2A related JITTERLY sample had previously been publicly analyzed and linked to Adaptix C2, an open-source framework used to control compromised systems during post-exploitation operations. TRU’s investigation connectsexp_enhanced.pyBy early August, the tooling had matured into exp_enhanced.py, a fully automated framework that could ingest a JSON target list, auto-register accounts with the word_word_NNN naming pattern, exploit each target, dumpFOFAand recon framework, we found that Red Heron had built a structured reconnaissance pipeline powered by FOFA, where they scanned 1,386 Gitea instances across seven countries, running 50-thread automated probes fromhashcatup its traces from the Gitea database afterward. SSH backdoor keys were planted on Green Oil's server. Hashcat was installed on the staging server for cracking stolen Gitea database credentials.HORKimhab/CVE-2026-60004exploit script.Within days of the advisory going public, the operator cloned a PoC from GitHub (HORKimhab/CVE-2026-60004) and started building on top of it on July 29, 2026. Tooling timestamps pulled from the staging
Countries
Argentinatelecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka.Canadaaerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka.Chinacontext, based on Simplified Chinese operational material, its classification of Taiwan as part of China, and targeting aligned with apparent strategic collection priorities. We have not identified sufficientIndiaOne of those targets, a famous overseas education consulting firm based out of India, was confirmed still running a vulnerable JCE editor version (2.9.99) at the time of our analysis. We also observed that the operatorQatarnot work here, it gives us a rough count of how many times Red Heron ran the chain against this target. A Qatar-based target also had data successfully pulled, including a learning management platform, an AI chatbot,Sri LankaConfirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka.TaiwanRed Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems. Targets were classified using Simplified Chinese labels covering defense, elections, energy,United Statesand research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka.
Industries
Aerospacesystems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada,Defensedataset of 477 Taiwan-based systems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromisesEducationEducation (.edu)Energysystems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations inFinancial ServicesGovernmentusing Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the UnitedHospitalityInformation TechnologyManufacturingWe found that the exfiltrated data from the Taiwanese manufacturing company was by far the largest. Upon investigation, we identified this target as a Taiwanese industrial automation company. The operator pulledResearchAcronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, aTelecommunicationswere classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina,