A China-linked threat actor known as Red Heron is exploiting a critical Gitea vulnerability to compromise government, defense, and research organizations across seven countries through automated attacks.
Key Points
- Red Heron weaponized the CVE-2026-60004 remote code execution vulnerability to scan 1,386 Gitea instances globally.
- The campaign utilizes a custom C++ Linux implant called JITTERLY and a stealthy rootkit named SIXZUT to maintain persistent access.
- Confirmed compromises include targets in the United States, Taiwan, Canada, Argentina, Qatar, and Sri Lanka.
- Attackers successfully moved laterally from compromised Gitea servers to gain root-level administrative access on a three-node Proxmox cluster.
- Stolen data includes source code, SSH keys, configuration secrets, and internal tokens from sectors including energy, aerospace, and telecommunications.