Threat Actor
Red Heron
- First Reported
- Sep 13, 2026
- Latest Reported
- Sep 13, 2026
Reported Context (1)
- Acronis TRU's name for the actor behind the Gitea exploitation and associated JITTERLY and SIXZUT activity. TRU assesses a PRC-linked operational context with moderate confidence and reports no established link to a previously tracked group. Red Heron Exploits Gitea CVE-2026-60004 in Multinational Campaign, Deploys Linux Rootkit
CVE (1)
Malware (2)
MITRE ATT&CK (11)
Vendors (1)
Products (7)
Tools (5)
Industries (11)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.