A cyber espionage group, identified as Red Heron, has been linked to the swift exploitation of a newly revealed vulnerability in Gitea. This breach has impacted several organizations across six countries, indicating a multi-national campaign.
Details of the Gitea Exploit
The Acronis Threat Research Unit (TRU) reported that Red Heron conducted a scan of 1,386 Gitea instances spanning seven countries. A specific focus was placed on 477 systems located in Taiwan. The threat actor’s activities evolved from stealing source codes to gaining persistent access and conducting credential collection. This included achieving root-level access to a Proxmox cluster comprising three nodes.
The attack compromised organizations in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka. Red Heron categorized its targets using Simplified Chinese, concentrating on sectors such as defense, telecommunications, aerospace, and research.
Technical Insights into Red Heron’s Methods
Red Heron is suspected of operating with connections to China, supported by the use of Simplified Chinese and a targeting strategy aligned with Chinese intelligence priorities. A detailed analysis of a staging server revealed a C++ Linux implant named JITTERLY, capable of executing over 30 post-exploitation commands. These include shell execution and network tunneling.
Additionally, a rootkit labeled SIXZUT was identified within the backdoor, able to conceal files and processes by altering multiple Linux functions. This allows the malware to operate undetected and persist even after termination.
Exploitation and Broader Impact
The exploitation of CVE-2026-60004, a significant Gitea remote code execution vulnerability, was weaponized by Red Heron. The group adapted publicly available exploit code into a sophisticated Python framework, swiftly implementing this strategy following the vulnerability’s disclosure in July 2026.
Within a short timeframe, Red Heron automated the process of registering accounts, exploiting vulnerable servers, and removing traces. This rapid adaptation highlights the risks posed by vulnerabilities in self-hosted development platforms, which can be leveraged to access sensitive information.
In Taiwan, Red Heron transitioned from a vulnerable Gitea instance to gaining root-level administrative access across a Proxmox cluster. Further investigations revealed the group’s strategies, which included targeting Joomla websites and exfiltrating sensitive data from various industries, including industrial automation and renewable energy.
Implications and Future Considerations
Red Heron’s campaign underscores the critical need for robust cybersecurity measures. The group’s focus on sectors such as elections, defense, and energy indicates a strategic intent to gather intelligence while opportunistically exploiting available vulnerabilities.
The incident serves as a reminder of the importance of promptly addressing newly disclosed vulnerabilities to prevent exploitation and protect sensitive information.
