"Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU) said in an analysis.
Acronis TRU links a rapid campaign to an actor it calls Red Heron
The Singapore cybersecurity company Acronis TRU attributed a multinational intrusion campaign to a suspected Chinese-linked threat actor it tracks as Red Heron, assessing that attribution with moderate confidence. Acronis cited three pieces of behavioural evidence: the use of Simplified Chinese in target labels, repeated classification of Taiwan as part of China, and a targeting footprint that aligns with the company's stated intelligence collection priorities.
The campaign produced confirmed compromises at 13 organizations across six countries: Canada (2), Argentina (1), Taiwan (4), the U.S. (4), Qatar (1), and Sri Lanka (1). Target sectors spanned defense, election, energy, aerospace, telecommunications, government, public safety, and research.
Weaponizing CVE-2026-60004 and turning PoC code into an automated framework
Acronis reported that Red Heron exploited CVE-2026-60004, a critical remote code execution vulnerability in Gitea. The actor moved quickly: beginning July 29, 2026, publicly available proof-of-concept code was converted into an automated Python framework named "exp_enhanced.py." Within days of the vulnerability's July 2026 disclosure, that framework could register accounts, exploit vulnerable servers, steal repositories, and remove selected traces, according to security researcher Subhajeet Singha, who is quoted in Acronis' analysis.
Parallel tooling found on a staging server showed the same infrastructure had earlier targeted 18 Joomla-based websites across 10 countries using a Python script named "exp.py" before cloning the Gitea exploit. Notable Joomla targets included an overseas education consulting firm based in India and a U.S.-based IT managed service provider.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageJITTERLY implant and the SIXZUT LD_PRELOAD rootkit
Examination of the staging server uncovered a C++ Linux implant that Acronis named JITTERLY. The implant supports more than 30 post-exploitation commands for tasks including shell execution, file transfer, process termination, network tunneling, interactive terminal access, and internal pivoting. JITTERLY had previously been documented in July 2026 by a researcher using the handle "dmpdump," who noted overlaps with an agent called AdaptixC2.
Embedded inside the backdoor was a previously undocumented LD_PRELOAD rootkit Acronis calls SIXZUT. The rootkit patches 15 different Linux functions to hide files, processes, and network connections, making malicious activity difficult to detect or terminate; Acronis reports SIXZUT can also relaunch if removed.
Operational tradecraft, lateral movement and documented exfiltration
Acronis details a campaign progression that moves from opportunistic scanning and repository theft to credential collection, persistent access, and lateral movement inside victim environments. In one Taiwanese environment, the actor advanced from a compromised Gitea server to root-level administrative access across a three-node Proxmox cluster.
Published findings list discrete exfiltration and reconnaissance results: extensive enumeration of an Argentine quantitative trading firm; theft of hundreds of repositories from a Taiwanese industrial automation company covering a SCADA/HMI tool, IoT platform integrations, a network sniffer, server configurations, a surveillance and monitoring product, and internal business applications; and data taken from a Qatar-based target including a learning management platform, an AI chatbot, workflow automation tools, and WordPress plugins. For a Canadian renewable energy company, repositories, configuration secrets, internal tokens, SSH host keys, and internal applications were exfiltrated.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: The campaign shows how quickly N-day vulnerabilities in self-hosted development platforms can be weaponized into automated frameworks that register accounts, steal repositories, and enable lateral movement. Teams responsible for internet-facing Gitea instances will be watching for signs of repository theft, unexpected accounts, credential harvesting, and evidence of implants such as JITTERLY or kernel/user-level hiding mechanisms like SIXZUT.
- Policymakers and regulators: The targeting of organizations associated with elections, defense, energy, government, and research—combined with tooling that classifies Taiwan as part of China—frames these intrusions as collection-focused and cross-border. Regulators tracking supply chains and data flows may now have fresh evidence of the risks posed by self-hosted code repositories and connected infrastructure.
- Affected enterprises and procurement leaders: The incidents documented by Acronis highlight that exfiltration from development platforms can expose not just source code but secrets, SSH keys, and tokens that permit deep lateral access—as shown by escalation to root across a three-node Proxmox cluster.
The Acronis analysis leaves a clear, practical lesson: a publicly disclosed proof-of-concept can become a highly automated, diversified espionage toolchain in days. For defenders and decision-makers, the immediate task is not hypothetical; it is to account for exposed repository infrastructure, inventory secrets tied to code, and the possibility that a single internet-facing service can yield access to an entire environment.




