Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-15 ยท updated: 2026-09-15 ยท tags: [incident, defence] ยท confidence: high ยท severity: critical ยท affected_sectors: [defence] ยท au_impact: true

Acronis's Threat Research Unit has published a full account of Red Heron, a Chinese-speaking actor it assesses with moderate confidence operates in a PRC-linked context, after tracing a Linux implant found during routine hunting back to the group's exposed staging server. The actor weaponised CVE-2026-60004, a critical remote-code-execution flaw in Gitea โ€” the self-hosted source-code management platform โ€” within days of a public proof-of-concept appearing on GitHub, and scanned 1,386 Gitea instances across seven countries, maintaining a structured target database of 477 Taiwan-based systems classified with Simplified Chinese labels covering defence, elections, energy, aerospace, telecommunications, government, public safety and research. Recovered records document confirmed compromises at organisations in Canada, Argentina, Taiwan, the United States and Sri Lanka, with activity progressing from source-code theft to credential collection, SSH persistence, backdoor deployment and lateral movement, including root-level access to a three-node Proxmox cluster. The staging server gave researchers rare visibility into the operation: it held the actor's exploitation tooling, reconnaissance databases, command history and stolen repositories, along with JITTERLY, a C++ Linux implant supporting more than 30 post-exploitation commands including shell execution, file transfer, network tunnelling and interactive terminal access. Embedded inside JITTERLY was SIXZUT, a previously undocumented LD_PRELOAD rootkit able to hide files, processes and network connections, prevent the implant being terminated, and relaunch it if the process is stopped while the binary remains. The tradecraft profile is deliberately commodity: a forked GitHub proof-of-concept, the Adaptix C2 framework and FOFA for reconnaissance, with no identified link to a previously tracked group. Acronis published mitigation and hunting guidance alongside the analysis, and the campaign is the sharpest current illustration of how quickly an n-day in developer tooling is converted into persistent access when the platform is reachable from the internet.

Attribute Detail
Sector Defence
Date 2026-09-15
Source Acronis Threat Research Unit
Reliability Tier 1
CVEs CVE-2026-60004