Red Heron Exploits Critical Gitea RCE Flaw to Deploy Linux Backdoor and Rootkit
A suspected Chinese-speaking threat actor, Red Heron, has been exploiting CVE-2026-60004, a critical remote code execution (RCE) vulnerability in Gitea (versions 1.17–1.27.0), to target internet-exposed source-code servers. The campaign, uncovered by Acronis Threat Research Unit, focuses on stealing proprietary repositories and deploying two malicious tools: the JITTERLY Linux backdoor and the SIXZUT rootkit.
The attack leverages Gitea’s vulnerable diffpatch API to gain remote execution, enabling threat actors to exfiltrate sensitive data including SCADA- and HMI-related source code from an industrial automation victim. The post-exploitation chain centers on JITTERLY, a C++ Linux implant with over 30 capabilities, such as remote shell execution, file transfers, SOCKS tunneling, and internal network pivoting.
To evade detection, Red Heron deploys SIXZUT, an LD_PRELOAD rootkit that conceals malicious files, processes, and network connections by intercepting Linux library functions. The rootkit also resists termination, automatically relaunching agents if stopped, and relies on /etc/ld.so.preload for persistence making cleanup risky without a full system rebuild.
Analysis of SIXZUT samples revealed an encrypted configuration linking to two JITTERLY agents:
- __hesti (p1.981666[.]xyz:6443)
- __root (p2.981666[.]xyz:8080)
These agents overlap with artifacts reported in 2026 HestiaCP intrusions, where administrators found unauthorized access and malicious files like /usr/lib/__hesti/__hesti and /lib/x86_64-linux-gnu/libnss_cache.so.2. The 981666[.]xyz infrastructure has also been tied to other Linux malware, including implants targeting UniFi devices, suggesting broader activity by the same or related actors.
Virlabs linked Red Heron to the theft of over 18,000 government records and exploitation across multiple device and software ecosystems, reinforcing the group’s sophisticated and persistent threat profile.
Source: https://cyberpress.org/red-heron-hackers-exploit-critical-gitea-rce-2/
Gitea cybersecurity rating report: https://www.rankiteo.com/company/gitea-org
Virlab, S.A. cybersecurity rating report: https://www.rankiteo.com/company/virlab
"id": "GITVIR1790403867",
"linkid": "gitea-org, virlab",
"type": "Breach",
"date": "1/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': 'Industrial Automation, Government',
'type': 'Industrial automation company, government '
'entities'}],
'attack_vector': 'Exploitation of CVE-2026-60004 (Gitea RCE vulnerability)',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': 'Over 18,000 government records',
'sensitivity_of_data': 'High (SCADA/HMI source code, '
'government records)',
'type_of_data_compromised': 'Source code (SCADA/HMI-related), '
'proprietary repositories, '
'government records'},
'description': 'A suspected Chinese-speaking threat actor, Red Heron, has '
'been exploiting CVE-2026-60004, a critical remote code '
'execution (RCE) vulnerability in Gitea (versions '
'1.17–1.27.0), to target internet-exposed source-code servers. '
'The campaign focuses on stealing proprietary repositories and '
'deploying two malicious tools: the JITTERLY Linux backdoor '
'and the SIXZUT rootkit. The attack leverages Gitea’s '
'vulnerable diffpatch API to gain remote execution, enabling '
'threat actors to exfiltrate sensitive data including SCADA- '
'and HMI-related source code from an industrial automation '
'victim. The post-exploitation chain centers on JITTERLY, a '
'C++ Linux implant with over 30 capabilities, such as remote '
'shell execution, file transfers, SOCKS tunneling, and '
'internal network pivoting. To evade detection, Red Heron '
'deploys SIXZUT, an LD_PRELOAD rootkit that conceals malicious '
'files, processes, and network connections by intercepting '
'Linux library functions.',
'impact': {'data_compromised': 'Proprietary repositories, SCADA- and '
'HMI-related source code, over 18,000 '
'government records',
'operational_impact': 'Unauthorized access, data exfiltration, '
'persistent backdoor access',
'systems_affected': 'Internet-exposed Gitea servers (versions '
'1.17–1.27.0), Linux systems'},
'initial_access_broker': {'backdoors_established': 'JITTERLY Linux backdoor, '
'SIXZUT rootkit',
'entry_point': 'Exploitation of CVE-2026-60004 '
'(Gitea RCE)',
'high_value_targets': 'SCADA/HMI source code, '
'proprietary repositories'},
'motivation': 'Cyber espionage, intellectual property theft, data '
'exfiltration',
'post_incident_analysis': {'root_causes': 'Unpatched Gitea servers '
'(CVE-2026-60004), lack of network '
'segmentation, insufficient '
'monitoring'},
'references': [{'source': 'Acronis Threat Research Unit'},
{'source': 'Virlabs'}],
'response': {'third_party_assistance': 'Acronis Threat Research Unit, '
'Virlabs'},
'threat_actor': 'Red Heron (suspected Chinese-speaking)',
'title': 'Red Heron Exploits Critical Gitea RCE Flaw to Deploy Linux Backdoor '
'and Rootkit',
'type': 'Cyber Espionage, Data Theft, Malware Deployment',
'vulnerability_exploited': 'CVE-2026-60004 (Gitea diffpatch API RCE)'}