Red Heron Exploits Gitea CVE-2026-60004 in Multinational Campaign, Deploys Linux Rootkit

· Original article ↗

Summary

Acronis researchers detail Red Heron’s exploitation of vulnerable Gitea servers to steal source code, collect credentials and move into victim networks, alongside analysis of the JITTERLY implant and embedded SIXZUT rootkit.

Key points

  • Red Heron weaponized critical Gitea remote code execution flaw CVE-2026-60004 within days of public proof-of-concept code. The flaw affects versions 1.17 through 1.27.0; Gitea patched it in version 1.27.1.
  • With open registration enabled, attackers could register an account and exploit the diffpatch endpoint without prior credentials. Red Heron scanned 1,386 Gitea instances across seven countries and compiled a separate list of 477 Taiwan-based systems.
  • Acronis documented compromises in Canada, Argentina, Taiwan, the United States and Sri Lanka, including repository theft, credential and secret collection, SSH persistence and lateral movement. One intrusion reached root-level control of a three-node Proxmox cluster.
  • The actor’s JITTERLY Linux implant supports more than 30 commands, including file transfer, shell execution, tunneling and network pivoting. It contains SIXZUT, an undocumented LD_PRELOAD rootkit that hides files, processes and network connections and helps restore the implant.
  • Acronis assesses with moderate confidence that Red Heron operated in a PRC-linked context, citing Simplified Chinese operational records, target classifications and victimology; researchers found no sufficient evidence linking it to a previously tracked group.
  • Acronis recommends upgrading Gitea to 1.27.1 or later, disabling unneeded open registration, investigating for signs of compromise and rotating credentials and secrets exposed in affected repositories. Confirmed compromises should be rebuilt rather than cleaned in place.

Article Details

Attack Vectors
  • Red Heron exploited CVE-2026-60004 in internet-facing Gitea instances. A crafted patch submitted twice forced Git's three-way merge path to write an executable hook into a bare temporary clone, resulting in code execution as the Gitea service account.
  • On Gitea instances with open registration, the actor created accounts and repositories to reach the writable diffpatch route without pre-existing credentials.
  • The actor used automated exploitation to collect repositories and Gitea data, planted SSH keys and backdoors, and moved from a compromised Taiwanese Gitea environment to root-level access on a three-node Proxmox cluster.
  • JITTERLY provided command execution, file transfer and internal-pivoting capabilities. Its embedded SIXZUT rootkit used LD_PRELOAD to conceal artifacts and connections and protect or relaunch the implant.
  • The operator also ran a separate campaign against 18 websites, 17 of which were confirmed to run Joomla. The exploited vulnerability and whether its `-shell` option successfully deployed backdoors were not established.
Defensive Notes
  • Upgrade Gitea to version 1.27.1 or later; disable unnecessary open registration, restrict the diffpatch route where unused, and avoid direct internet exposure where authenticated access is practical.
  • Review recently created Gitea accounts and repositories, diffpatch requests, and requests to `/api/v1/metrics` with unfamiliar query parameters. Investigate Gitea processes spawning shells, interpreters or curl.
  • Inspect `/etc/ld.so.preload`, unauthorized `authorized_keys` entries, and outbound reverse-shell or beacon traffic. Hunt for `libglthread.so.2`, `.ld_aux_cahe` and `/tmp/.X11-unix.lk` using trusted offline, kernel-level or EDR evidence because SIXZUT can hide them from live userland tools.
  • If compromise is confirmed, rebuild affected hosts rather than relying on live removal. Assume repositories were taken, inspect them for further secrets, and rotate credentials, tokens and SSH host keys stored in the compromised Gitea instance.

Indicators of compromise

TypeIndicatorContext
DOMAIN981666[.]xyzParent domain listed with JITTERLY command-and-control infrastructure.
DOMAINs2[.]981666[.]xyzJITTERLY command-and-control domain.
DOMAINxcyoibfhuufz[.]comRelated domain listed among the campaign's network indicators.
IPV472[.]11[.]138[.]109Red Heron's staging server.
SHA25628b132ad55bd310bb5cf3ddb4ace580529ad735204a48cf388830d9039843d8eSHA-256 of the SIXZUT rootkit decrypted from JITTERLY.
SHA256b441f793c87e54cb7e3f7205e25442aa19920d325cb6af41d2afdc8a0b5cf54fSHA-256 of the JITTERLY implant, listed as agent.elf.

MITRE ATT&CK

T1014 · RootkitSIXZUT is an LD_PRELOAD rootkit that hides files, processes and network connections and interferes with termination of the implant.T1027 · Obfuscated Files or InformationJITTERLY carries an AES-encrypted SIXZUT rootkit blob, while SIXZUT decrypts sensitive strings at runtime.T1070.004 · File DeletionThe automated exploit framework attempted to remove selected traces from the Gitea database after exploitation.T1098.004 · SSH Authorized KeysThe operator planted SSH keys in a compromised server's authorized_keys file for persistent access.T1110.002 · Password CrackingThe operator used hashcat to crack stolen Gitea database credentials stored as bcrypt hashes.T1190 · Exploit Public-Facing ApplicationRed Heron exploited CVE-2026-60004 on internet-facing Gitea instances to execute code as the Gitea service account.T1213.003 · Code RepositoriesRed Heron's exploitation framework dumped repositories from compromised Gitea servers, and recovered staging-server folders contained stolen source code.T1552.001 · Credentials In FilesThe operator extracted JWT tokens, internal tokens and SSH host keys from Gitea configuration on a compromised company's server.T1573.001 · Symmetric CryptographyJITTERLY encrypts its custom TCP command-and-control messages with per-session AES-128-GCM keys.T1574.006 · Dynamic Linker HijackingSIXZUT writes its shared-library path to `/etc/ld.so.preload`, causing dynamically linked processes to load the rootkit.T1595 · Active ScanningThe actor scanned 1,386 Gitea instances and probed for open registration before prioritizing targets.

CVE

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Aerospacesystems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada,Defensedataset of 477 Taiwan-based systems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromisesEducationEducation (.edu)Energysystems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations inFinancial ServicesGovernmentusing Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the UnitedHospitalityInformation TechnologyManufacturingWe found that the exfiltrated data from the Taiwanese manufacturing company was by far the largest. Upon investigation, we identified this target as a Taiwanese industrial automation company. The operator pulledResearchAcronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, aTelecommunicationswere classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina,

Related Articles