Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit
Brief
A suspected Chinese-speaking threat actor tracked as Red Heron is exploiting the critical Gitea remote code execution vulnerability tracked as CVE-2026-60004.
The operation targeted internet-exposed source-code servers, enabling the theft of proprietary repositories and deployment of the JITTERLY Linux backdoor alongside the stealth-focused SIXZUT rootkit.
Acronis Threat Research Unit reported that Red Heron rapidly weaponized the Gitea flaw, affecting versions 1. 17 through 1.
- 0, to gain remote execution through the platform’s vulnerable diffpatch API.
Red Heron Hackers Exploit Critical Gitea RCE
The campaign reportedly targeted organizations across multiple countries, stealing data including repositories from an industrial automation victim containing SCADA- and HMI-related source code.
