Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A suspected Chinese state-linked threat actor named Red Heron has actively exploited the critical remote code execution vulnerability CVE-2026-60004 in Gitea, resulting in confirmed compromises across thirteen organizations in six countries. The campaign, which began shortly after the flaw's disclosure, involves automated scanning and exploitation to steal source code, credentials, and internal infrastructure details from victims in sectors such as defense, energy, and government.
The attackers deployed a Linux implant called JITTERLY along with a newly discovered LD_PRELOAD rootkit named SIXZUT to maintain persistence and evade detection by hiding processes and files. Analysis indicates that the group achieved root-level access on some victim networks, including moving laterally through a three-node Proxmox cluster in Taiwan.