Back to News
Threat Intelligence

Red Heron Exploits Gitea RCE to Compromise Organizations Across Six Countries

Cyber RTSeptember 15, 20263 min read
Red Heron Exploits Gitea RCE to Compromise Organizations Across Six Countries

Red Heron, a threat actor, exploited a Gitea vulnerability to compromise systems across seven countries, including Taiwan, Canada, Qatar and the U.S. The campaign involved source-code theft, credential collection, and root-level access, targeting sectors like defense and energy. Red Heron used a C++ implant, JITTERLY, and a rootkit, SIXZUT, for post-exploitation. The actor rapidly adapted public code into an automated framework for attacks.

A threat actor known as Red Heron has been linked to the rapid exploitation of a newly disclosed security vulnerability in Gitea, a self-hosted development platform. This exploitation was part of a multi-national campaign targeting internet-facing instances. The Acronis Threat Research Unit (TRU) reported that Red Heron scanned 1,386 Gitea instances across seven countries, maintaining a separate dataset for 477 systems based in Taiwan. The campaign involved activities ranging from source-code theft to gaining persistent access, collecting credentials, and achieving lateral movement, including obtaining root-level access to a three-node Proxmox cluster. The campaign has resulted in confirmed compromises of organizations in several countries, including Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka. The threat actor used Simplified Chinese labels to classify targets, which spanned sectors such as defense, election, energy, aerospace, telecommunications, government, public safety, and research. An analysis of a staging server linked to Red Heron revealed a C++ Linux implant named JITTERLY, which supports over 30 post-exploitation commands. These commands are related to shell execution, file transfer, process termination, network tunneling, interactive terminal access, and internal pivoting. JITTERLY shares similarities with the AdaptixC2 agent, as documented by a researcher known as "dmpdump" in July 2026. The backdoor also contains a previously undocumented LD_PRELOAD rootkit called SIXZUT, capable of concealing files, processes, and network connections. Red Heron exploited CVE-2026-60004, a critical Gitea remote code execution vulnerability, to scan thousands of instances across seven countries. The group transformed a publicly available exploit for the flaw into an automated Python framework, "exp_enhanced.py," shortly after the vulnerability's disclosure in July 2026. This framework allowed for automated account registration, exploitation of vulnerable servers, repository theft, and trace removal. Security researcher Subhajeet Singha noted the rapid adaptation of public proof-of-concept code and open-source tools, without evidence of artificial intelligence involvement. In Taiwan, Red Heron progressed from a vulnerable Gitea server to root-level administrative access across a three-node Proxmox cluster. The threat actor used the same infrastructure to target 18 Joomla-based websites across 10 countries, employing a Python script before cloning the CVE-2026-60004 exploit. Targets included an overseas education consulting firm in India and a U.S.-based IT managed service provider. The campaign involved extensive enumeration of an Argentine quantitative trading firm and exfiltration of data from a Taiwanese industrial automation company. Data exfiltration from a Qatar-based target included a learning management platform, an AI chatbot, workflow automation tools, and WordPress plugins. Red Heron also conducted extensive infrastructure mapping of a Canadian renewable energy company, exfiltrating repositories, configuration secrets, internal tokens, SSH host keys, and internal applications. JITTERLY was deployed in confirmed compromises, but specific target details remain undisclosed due to ongoing investigations. The campaign demonstrates how quickly N-day vulnerabilities in self-hosted development platforms can expose sensitive information. By combining automated Gitea exploitation with structured target selection, Red Heron advanced from repository theft to credential collection, persistent access, and lateral movement across victim environments. The focus on organizations linked to elections, defense, energy, government, and research indicates deliberate collection priorities alongside broader opportunistic scanning.