Skip to content
Red Heron Exploits Gitea Vulnerability in Multinational Cyber Campaign

Red Heron Exploits Gitea Vulnerability in Multinational Cyber Campaign

First seen 14 Sep 2026, 17:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 18:17 UTC
  • Red Heron exploited CVE-2026-60004 in Gitea, affecting 1,386 instances across seven countries.
  • The campaign involved source-code theft and lateral movement, impacting multiple sectors.
  • JITTERLY implant and SIXZUT rootkit were used for post-exploitation activities.

A Chinese-speaking threat actor known as Red Heron has exploited CVE-2026-60004, a recently disclosed remote code execution vulnerability in Gitea, to compromise 1,386 instances across seven countries. The campaign has led to confirmed breaches affecting organizations in Canada, Argentina, Taiwan, the United States, Qatar, and Sri Lanka. Red Heron utilized an automated framework to scan for vulnerabilities, leading to source-code theft, credential collection, and lateral movement within compromised networks. The actor's operations included root-level access to a three-node Proxmox cluster and the deployment of a C++ Linux implant named JITTERLY, which supports over 30 post-exploitation commands. Additionally, a previously undocumented rootkit, SIXZUT, was discovered, capable of hiding malicious activities. The rapid exploitation of this n-day vulnerability highlights the risks associated with self-hosted development platforms. Current assessments indicate Red Heron operates within a context linked to the People's Republic of China.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-29
Public PoC for CVE-2026-60004 released
A proof-of-concept code was made available, demonstrating the vulnerability's exploitation potential.
Acronis
2026-08-25
CVE-2026-60004 added to CISA KEV
CISA included the vulnerability in its Known Exploited Vulnerabilities catalog due to active exploitation.
Acronis
2026-08-26
CVE-2026-60004 published
The vulnerability was officially published, detailing its critical nature and impact on Gitea instances.
Acronis
2026-09-14
Red Heron's campaign reported
Acronis Threat Research Unit detailed the multinational campaign and its implications for affected organizations.
Acronis

More articles in this cluster (5)

Following this threat?

Track Red Heron, Jitterly and CVE-2026-60004 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed