IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Red Heron exploits Gitea flaw, uncovers SIXZUT rootkit

Red Heron exploits Gitea flaw, uncovers SIXZUT rootkit

Mon, 28th Sep 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Acronis Threat Research Unit has identified a multinational campaign by a threat actor it calls Red Heron that exploited a flaw in self-hosted Gitea servers. The researchers also uncovered a previously undocumented Linux rootkit called SIXZUT.

The findings point to the rapid weaponisation of newly disclosed software flaws against internet-facing development systems used to manage source code and related infrastructure.

The activity centred on CVE-2026-60004, a critical remote code execution vulnerability in Gitea, an open-source source code management platform. According to Acronis, the actor turned public proof-of-concept code into an automated attack framework within days, allowing it to register accounts on exposed systems, run the exploit, steal repositories and remove some traces of its activity.

Acronis tracked the operation as Red Heron and observed confirmed compromises in Canada, Argentina, Taiwan, the United States and Sri Lanka. Internal target data reviewed by the researchers also referenced sectors including government, telecommunications, energy, defence, aerospace and research.

Rapid shift

The report adds to growing evidence that attackers are moving quickly from disclosure to exploitation, especially when development tools are directly reachable from the internet. In this case, Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 systems in Taiwan.

Those systems were reportedly labelled in Simplified Chinese and prioritised by sector and perceived value. Acronis said that pattern, along with other operational material, supported an assessment with moderate confidence that the actor operated in a PRC-linked context, although it did not link the campaign to any known threat group.

The campaign went beyond source code theft. The intrusions involved credential collection, SSH persistence, backdoor deployment and lateral movement after initial access.

In one case in Taiwan, the attacker moved from a vulnerable Gitea server to root-level administrative access on a three-node Proxmox cluster. Acronis said the actor obtained a Proxmox root authentication ticket, uploaded payloads to all three nodes and started virtual machine backup operations that could have enabled the collection of full disk images, not just repositories.

Rootkit discovery

While investigating the operation, the researchers traced a Linux implant known as JITTERLY to an exposed staging server used by Red Heron. They said the server contained exploitation tools, targeting data, command history, stolen repositories and malware, giving them unusual visibility into how the campaign was run.

JITTERLY is a C++ Linux implant linked to the same operation and designed for post-compromise activity. It supports more than 30 commands, including shell execution, file transfer, network tunnelling, interactive terminal access and internal pivoting.

Embedded in JITTERLY was SIXZUT, which the researchers described as an LD_PRELOAD rootkit for Linux. They said it could hide files, processes and network connections, prevent the implant from being terminated and relaunch it if the process was killed while the binary remained on disk.

The rootkit was disguised as a shared library and configured to load through the system's LD_PRELOAD mechanism. According to the researchers, it filtered access to selected files, concealed process entries under /proc, hid network connections from common userland tools and intercepted signals intended to kill protected processes.

Development targets

The report underlines the value attackers place on development platforms, which often hold source code, credentials, secrets and internal configuration data. In one compromise in the renewable energy sector, the attacker gained repeated access to application stacks, authentication systems, intranet services and internal reports, along with deployment keys and other secrets.

In another case, a Taiwanese industrial automation company lost hundreds of repositories from a single host. The reportedly stolen material included surveillance and monitoring products, industrial control software, internet of things integrations, network tools and internal business applications.

The operation also appears to have run in parallel with a separate campaign against Joomla-based websites. Acronis said the same staging infrastructure was tied to attacks on 18 mostly Joomla sites across 10 countries, although it could not confirm the exact vulnerability used.

Patch pressure

The Acronis account highlights the narrowing patch window for organisations running self-hosted software development tools. Gitea patched the flaw in version 1.27.1, but the researchers said the actor was already adapting publicly available exploit code and testing it against live targets within days.

That speed is likely to concern security teams, particularly in sectors operating internet-facing collaboration and software delivery systems. Exposure can extend far beyond a single application because repository servers may provide routes into broader infrastructure, credentials, internal networks and virtualised environments.

"This campaign highlights that internet-facing development platforms can provide access not only to source code, but also to credentials, application secrets, deployment infrastructure, and connected systems," said Subhajeet Singha, author at Acronis.

"Rapid patching, restricted account registration, and close monitoring of self-hosted development environments are therefore essential to preventing an initial repository-server compromise from becoming a broader infrastructure breach," Singha said.