14-09-2026
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
Report completeness: High
Actors/Campaigns:
Red_heron
Threats:
Jitterly
Sixzut
Hashcat_tool
Netcat_tool
Adaptixc2_tool
Victims:
Defense, Elections, Energy, Aerospace, Telecommunications, Government, Research, Gitea instances, Joomla websites, Quantitative trading, have more...
Industry:
Education, Energy, Telco, Military, Petroleum, Aerospace, Government
Geo:
China, Argentina, Canada, Taiwanese, United states, Taiwan, Chinese, India, Qatar, Sri lanka, Canadian
CVEs:
CVE-2026-60004 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- gitea (<1.27.1)
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1005, T1014, T1016, T1020, T1021.004, T1027.009, T1027.013, T1036, T1059.004, T1070.004, have more...
IOCs:
File: 4
Domain: 3
IP: 1
Hash: 2
Soft:
Linux, twitter, Joomla, nginx, curl, WordPress, Docker, UNIX, OpenGL
Algorithms:
aes, bcrypt, aes-128-ctr, aes-128, aes-128-gcm, crc-32, sha1, xor, aes-256-gcm
Functions:
setsid, dup2, chdir, sys_geteuid_wrapper, get_self_path, file_contains_string, read, fopen, kill
Win API:
gethostname, getsockname
Languages:
python
Links:
https://github.com/HORKimhab/CVE-2026-60004