Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit
Red Heron exploited Gitea CVE-2026-60004 to steal repositories and deploy the JITTERLY backdoor and SIXZUT rootkit.
Acronis and Virlabs say Red Heron weaponized critical Gitea RCE CVE-2026-60004 against internet-exposed self-hosted servers, including an industrial automation organization. Attackers stole hundreds of repositories, including SCADA and HMI source code, collected credentials, moved laterally, and tried to take virtual-machine images. They deployed JITTERLY, a C++ Linux backdoor with more than 30 capabilities, and SIXZUT, an LD_PRELOAD rootkit that hides files, processes, and connections. Related 981666.xyz infrastructure has been tied to WordPress, UniFi, Gitea, and ZyXEL activity and theft of more than 18,000 government records.