Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Malware

A Chinese-speaking threat actor tracked as Red Heron has exploited a remote-code-execution vulnerability in Gitea to steal source code, establish persistence, and deploy a previously undocumented Linux rootkit.

The campaign weaponized CVE-2026-60004, a CVSS 9.8 flaw in Gitea’s diffpatch functionality, within days of public proof-of-concept code emerging in July. The vulnerability affects Gitea versions 1.17 through 1.27.0 and was fixed in version 1.27.1.

Red Heron allegedly scanned 1,386 Gitea instances across seven countries and assembled a separate collection of 477 Taiwan-based systems.

Red Heron Hackers Exploit Critical Gitea RCE

Recovered reconnaissance data categorized organizations including defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed intrusions involved victims in Canada, Argentina, Taiwan, the United States, and Sri Lanka.

The flaw allows a malicious repository patch to cause Git to write an attacker-controlled hook into an active hook directory. When Git later accesses its index, that hook executes under the Gitea service account.

Although the diffpatch endpoint requires repository write access, open account registration enabled by default in some deployments allowed attackers to create accounts and repositories before exploitation.

Gitea RCE (Source: acronis)
Gitea RCE (Source: acronis)

After adapting a public GitHub proof of concept, the operators built automation that tested registrations, exploited vulnerable servers, copied repository data, and attempted to remove artifacts from Gitea databases. They also used Hashcat against stolen Gitea database credentials and planted SSH keys for persistence.

TRU reported that Red Heron moved beyond code-theft activity in several environments. At a Canadian renewable-energy company, the actor accessed application stacks, services, secrets, JWTs, tokens, and SSH host keys.

In Taiwan, the group obtained a root Proxmox authentication ticket after compromising a Synology-hosted Gitea server, uploading payloads to three cluster nodes and initiating virtual-machine backup operations.

Researchers linked the operation to JITTERLY, a C++ Linux ELF implant compatible with elements of the Adaptix C2 protocol.

The backdoor supports more than 30 functions for command execution, file transfer, SOCKS and TCP tunneling, reverse port forwarding, interactive terminals, reconnaissance, and internal pivoting. Its traffic uses raw TCP, MessagePack serialization, and AES-128-GCM encryption.

JITTERLY also decrypts and installs an embedded LD_PRELOAD rootkit dubbed SIXZUT. The rootkit disguises itself as libglthread.so.2 and hides files, processes, and connections, blocks termination, and relaunches the implant. Because it is loaded through /etc/ld.so.preload, live-host cleanup may be unreliable.

Acronis assesses with moderate confidence that Red Heron operates in a PRC-linked context, citing Simplified Chinese artifacts, Taiwan’s classification in the data, and targeting consistent with strategic collection. The company found no conclusive connection to a known APT group.

Organizations running self-hosted Gitea should upgrade to version 1.27.1 or newer, disable unnecessary open registration, review accounts and diffpatch requests, and investigate unexpected child processes launched by Gitea.

Defenders should also audit authorized_keys, rotate secrets held in exposed repositories, and inspect /etc/ld.so.preload from trusted offline media or endpoint telemetry.

Where SIXZUT infection is confirmed, researchers recommend rebuilding affected hosts rather than attempting in-place remediation, and preserving forensic evidence before recovery begins safely.

Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories