China-linked threat actor Red Heron exploited CVE-2026-60004, a critical remote-code-execution vulnerability in Gitea, to compromise 13 organizations in Canada, Argentina, Taiwan, the United States, Qatar, and Sri Lanka. After the flaw’s public disclosure, the operator scanned 1,386 Gitea servers across seven countries and separately tracked 477 systems in Taiwan, targeting organizations in defense, elections, energy, aerospace, telecommunications, government, public safety, and research.
Red Heron integrated public proof-of-concept code into a Python automation framework that created accounts, exploited exposed servers, exfiltrated repositories, and selectively removed evidence. The intrusions stole source code, credentials, secrets, tokens, SSH keys, and internal applications; in one Taiwanese victim, the actor moved laterally to root-level access across a three-node Proxmox cluster. The group maintained access with the JITTERLY Linux implant and its embedded SIXZUT LD_PRELOAD rootkit, enabling covert persistence, post-exploitation activity, and evasion.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Red Heron began using the Python framework exp_enhanced.py, which automated account registration, exploitation of vulnerable Gitea servers, repository theft, and selected trace removal.
CVE-2026-60004, a critical remote-code-execution vulnerability affecting Gitea, was disclosed in July 2026.
In a Taiwanese victim environment, Red Heron pivoted from a compromised Gitea server to root-level administrative access across a three-node Proxmox cluster.
Red Heron deployed the C++ Linux implant JITTERLY, which supports more than 30 post-exploitation capabilities and contains the undocumented SIXZUT LD_PRELOAD rootkit for hiding files, processes, and network connections and resisting removal.
The actor exfiltrated source repositories and sensitive materials including configuration secrets, internal tokens, SSH keys, and internal applications from victims including Taiwanese industrial automation, Qatari, and Canadian renewable-energy organizations.
Red Heron's Gitea campaign compromised two organizations in Canada; one each in Argentina, Qatar, and Sri Lanka; and four each in Taiwan and the United States. Targeted sectors included defense, elections, energy, aerospace, telecommunications, government, public safety, and research.
The actor scanned 1,386 internet-facing Gitea instances across seven countries and maintained a separate dataset covering 477 systems in Taiwan.
Before adopting the Gitea exploit, Red Heron used the same infrastructure and a Python script named exp.py to target 18 Joomla websites, including an India-based education consulting firm and a U.S.-based managed service provider.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.