CTIPilot

Red Heron

actor · actor:red-heron

Chinese-speaking, PRC-linked (moderate confidence) cluster first profiled by Acronis Threat Research Unit (2026-09-13) for rapid n-day weaponisation of a Gitea flaw (CVE-2026-60004) with the JITTERLY Linux implant and an embedded SIXZUT LD_PRELOAD rootkit. GreyNoise (2026-09-21) assesses, with hedged confidence ("same or related to"), that an actor it has tracked since 7 May 2026 exploiting CVE-2026-7273 (Zyxel GS1900 switches) and a WordPress WP2Shell exploit chain is this same cluster, based on a shared C2 domain, malware family, Gitea exploitation and other TTPs.

Coverage timeline
2
first 2026-08-30 → last 2026-09-22
Peak priority
high
2 high
Sources cited
6
6 hosts
Sections touched
2
deep-dive, trending-vulnerabilities
Co-occurring entities
6
see Co-occurring entities below
ATT&CK techniques
11
pinned v19.2 · see below
2026-08-302 appearances2026-09-22

ATT&CK techniques

11 techniques observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

Execution TA0002

T1059.004Command and Scripting Interpreter: Unix Shell×1

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · ATT&CK page ↗

T1574.006Hijack Execution Flow: Dynamic Linker Hijacking×1

Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as <code>LD_PRELOAD</code> on Linux or <code>DYLD_INSERT_LIBRARIES</code> on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

Stealth TA0005

T1014Rootkit×1

Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

T1574.006Hijack Execution Flow: Dynamic Linker Hijacking×1

Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as <code>LD_PRELOAD</code> on Linux or <code>DYLD_INSERT_LIBRARIES</code> on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · ATT&CK page ↗

Command and Control TA0011

T1090.001Proxy: Internal Proxy×1

Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

T1095Non-Application Layer Protocol×1

Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

T1105Ingress Tool Transfer×2

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

Impact TA0040

T1496Resource Hijacking×1

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev · ATT&CK page ↗

Story timeline

  1. 2026-09-22CVE-2026-7273, Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries
    deep-diveCISA adds a pre-auth Zyxel switch RCE to KEV after GreyNoise catches a Red Heron-linked actor exploiting it at scale
  2. 2026-08-30CVE-2026-60004: Gitea's diffpatch endpoint turns an attacker-supplied patch into a live Git hook, giving command execution as the service account; KEV-listed after miner deployment
    trending-vulnerabilitiesApplying the same patch twice writes an executable into $GIT_DIR of a bare clone, and Git then runs it as the Gitea user

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

exploits

Where this entity is cited

  • trending-vulnerabilities1
  • deep-dive1

Source distribution

  • acronis.com1 (17%)
  • cisa.gov1 (17%)
  • github.com1 (17%)
  • greynoise.io1 (17%)
  • helpnetsecurity.com1 (17%)
  • zyxel.com1 (17%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Red Heron (2)

2026-08-30 · view entry permalink →

HIGHCVE-2026-60004exploitedupdatedNATOA1

CVE-2026-60004: Gitea's diffpatch endpoint turns an attacker-supplied patch into a live Git hook, giving command execution as the service account; KEV-listed after miner deployment

CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on 2026-08-25. The flaw is in services/repository/files/patch.go, the code behind Gitea's diffpatch endpoint, which applies an attacker-controlled patch inside a shared bare temporary clone. The maintainers describe the chain precisely: "submitting the same patch twice creates an add/add collision. Git's three-way fallback checks the indexed path out even though the operation is performed with --cached" (Gitea maintainers, 2026-07-28). In a bare clone the repository root is $GIT_DIR, so a checked-out executable entry whose path matches a Git hook name is not a file sitting next to the hooks directory, it is a hook. Git then invokes it while writing the index, and it runs as the Gitea OS account.

The precondition is the part worth reading twice. The advisory states it plainly: "an attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository" (same advisory). Ordinary write access is not a privileged role, it is what every user of a Git forge has by definition, and Gitea's shipped default hands it to anyone who can reach the login page. So on a default-configured instance this is a pre-authentication flaw in every sense that matters operationally, separated from an anonymous visitor only by a registration form. Fixed in Gitea 1.27.1. The advisory carries a working proof-of-concept, which arrived with it.

Exploitation is opportunistic and automated. Help Net Security reports the incident write-up of an operator whose self-hosted instance was compromised: "because the server ran an outdated version of Gitea, with open user registration and no email confirmation or CAPTCHA, an automated scanner was able to register an account, create its own repository, and trigger the exploit chain" (Help Net Security, 2026-08-26). The chain wrote a proof of execution into a Git branch, then pulled a shell loader followed by a miner; the operator was alerted not by security tooling but by the hosting provider flagging sustained CPU. That is a mass-scanning profile against a default configuration, not targeted intrusion, and it means exposure is a function of being reachable rather than being interesting.

The blast radius is broader than the payload suggests. Depending on container isolation and the privileges of the Gitea OS user, exploitation can expose the main configuration file, application and process-environment secrets, database credentials and contents, and OAuth and integration credentials (same reporting). A miner is the noisy outcome; the quiet one is a set of credentials into whatever the forge is wired to, which for a public-sector development estate typically means CI runners, artefact registries and identity providers.

Where the activity surfaces. The exploitation itself looks like ordinary API traffic, so the durable signal is what the service account does immediately afterwards. Watch for the Gitea service account spawning a shell or an interpreter within seconds of a patch or diff API call, on a host whose normal process tree is a Go binary plus git. On the repository side, the artefact is a Git hook whose content arrived through patch application rather than through an administrator action, so an executable object at a hook path in a repository nobody manages is the thing to hunt for. Registration and repository-creation events are the leading indicator: on an instance with real users, a self-registered account creating a single repository and immediately exercising the diff endpoints is not a normal usage pattern.

Triage: the benign lookalike is a legitimate developer using diffpatch to apply a patch, which is what the endpoint is for and which will be the overwhelming majority of hits on that route. Two things separate exploitation from it. First, the same patch applied twice in quick succession, which is the collision the attack requires and which a human working normally has no reason to produce. Second, and more reliably, what happens next: a legitimate patch application ends with a commit, while this one ends with the service account executing something. Alert on the process behaviour, use the endpoint traffic to explain it.

An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository.

Submitting the same patch twice creates an add/add collision. Git's three-way fallback checks the indexed path out even though the operation is performed with --cached.

Gitea maintainers (GitHub Security Advisory) 2026-07-28

Because the server ran an outdated version of Gitea, with open user registration and no email confirmation or CAPTCHA, an automated scanner was able to register an account, create its own repository, and trigger the exploit chain.

Help Net Security 2026-08-26

Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems. Targets were classified using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka.

The staging server also contained JITTERLY, a C++ Linux implant supporting more than 30 post-exploitation commands, including shell execution, file transfer, network tunneling, interactive terminal access, and internal pivoting. Embedded inside it was SIXZUT, a previously undocumented LD_PRELOAD rootkit capable of hiding files, processes, and network connections, preventing the implant from being terminated, and relaunching it if the process is stopped while the binary remains present.

Acronis Threat Research Unit 2026-09-13
Updaterun 2026-09-22T0410Z-intelentitiestechniquestagssourcesevidencebody

Acronis Threat Research Unit documents a second, targeted exploitation of this same vulnerability, distinct from the opportunistic cryptomining incident above: a Chinese-speaking actor it tracks as Red Heron, assessed with moderate confidence to operate in a PRC-linked context, turned public proof-of-concept code into an automated exploitation framework within days of the July 2026 advisory (Acronis Threat Research Unit, 2026-09-13). The actor scanned 1,386 Gitea instances across seven countries and maintained a separate target list of 477 Taiwan-based systems, classifying candidates by sector (defense, elections, energy, aerospace, telecommunications, government and research) and confirmed compromises in Canada, Argentina, Taiwan, the United States and Sri Lanka, including source-code theft, credential collection, SSH-key persistence and lateral movement (Acronis Threat Research Unit, 2026-09-13). In one Taiwanese environment the actor escalated from the Gitea compromise to an obtained Proxmox root authentication ticket, reaching root-level administrative access across a three-node Proxmox cluster and initiating full virtual-machine backup operations that would have exfiltrated complete VM disk images had they completed.

Acronis traced a Linux implant, which it tracks as JITTERLY, to Red Heron's own exposed staging server. JITTERLY is a C++ implant compatible with the Adaptix C2 framework's protocol, communicating over raw TCP with msgpack-serialized, AES-128-GCM-encrypted messages, and supporting more than 30 post-exploitation commands including SOCKS/TCP tunneling, reverse port forwarding, internal pivot relaying and an interactive terminal (Acronis Threat Research Unit, 2026-09-13). Embedded inside JITTERLY as an encrypted blob is a previously undocumented LD_PRELOAD rootkit Acronis tracks as SIXZUT, which hooks libc file, directory, socket and signal-handling functions to hide its own files, hide matching processes from /proc listings, hide matching network connections from /proc/net/* reads and netlink socket queries alike, and re-launch the implant if it is killed while the rootkit's own library remains loaded via /etc/ld.so.preload (Acronis Threat Research Unit, 2026-09-13).

Detection (Red Heron / JITTERLY / SIXZUT specific): an unexplained entry or modification to /etc/ld.so.preload is a strong signal on any Linux host, since this file is normally absent or static; because SIXZUT hides its own artifacts from userland tools, check /etc/ld.so.preload, running-process lists and /proc/net/* contents from a known-good offline image, a different host, or kernel-level/EDR telemetry rather than ls, ps, netstat or ss run on the live host itself. A kill -9 against a hidden PID that returns with no error but leaves the process running is consistent with SIXZUT's signal-hiding hook. On any Gitea instance that also fronts a Proxmox or similar virtualization API, treat a Gitea-stored credential or token reaching that management API as a lateral-movement path, not just a data-exfiltration one.

Defender takeaway (update): the same patch and registration hardening above close both the opportunistic and the targeted exploitation paths; an instance that was internet-reachable and unpatched should now also be checked for the Red Heron / JITTERLY / SIXZUT artifacts above, not only for a cryptominer, since this actor's confirmed objective on comparable targets was credential theft and persistent access rather than resource abuse.

vulnerability30 Aug 13:12Zmulti-sourceOpen finding ↗

2026-09-22 · view entry permalink →

HIGHCVE-2026-7273exploitedNATOB1

CVE-2026-7273, Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series smart-managed switch firmware that lets a LAN-based, unauthenticated attacker execute OS commands via a crafted HTTP request to the switch's web-management interface (Zyxel PSIRT, 2026-06-16). Zyxel patched all ten affected models (GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, -48 and -48HPv2) on 2026-06-16, each at its own "…(x).2C0" build one increment above the vulnerable "…(x).1C0 and earlier" baseline (Zyxel PSIRT, 2026-06-16). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-21, acting on GreyNoise sensor-grid research published the same day: GreyNoise has tracked a single malicious cyber actor since 7 May 2026, a suspected Chinese speaker possibly working in UTC+8 based on Chinese-language code comments and operational timing, that it assesses is the same as or related to Red Heron, a Chinese-speaking, PRC-linked cluster Acronis Threat Research Unit profiled on 2026-09-13 for rapid n-day weaponisation of a Gitea flaw (Acronis Threat Research Unit, 2026-09-13), based on a shared command-and-control domain, malware family and other overlapping tradecraft (GreyNoise, 2026-09-21).

On or about 17 August 2026 the actor exploited CVE-2026-7273 with a PyArmor-6.7.5-obfuscated Python tool offering two modes: a deterministic single-request GOT-overwrite, and an ASLR-brute-force stack mode averaging roughly 2,048 attempts, explicitly targeting firmware versions 2.10-2.90 of the GS1900-24, while also providing command-line options for the target's libc base address and GOT offsets that GreyNoise states could be used to target other firmware in scope for the vulnerability (GreyNoise, 2026-09-21). The actor exfiltrated configuration data, networking information and hashed root-level credentials from 996 Zyxel GS1900 switches across 48 countries, making the switch's on-device shell fetch a TFTP-delivered collector script and stage the harvested data to a file on the switch for retrieval (GreyNoise, 2026-09-21). "While the credentials were hashed, 564 of the victims had factory default credentials" (GreyNoise, 2026-09-21), for the majority of victims the exfiltrated hash was unnecessary, since the unrotated default password alone gave the actor durable re-entry.

GreyNoise frames the Zyxel exploitation as one prong of a broader, opportunistic operation: the same actor separately exploited an already-KEV-listed Ubiquiti UniFi OS chain and ran a WordPress exploit chain that compromised at least 49 organizations in 29 countries from 20 July onward, with the worst confirmed case, an unnamed Western government, losing over 18,000 sensitive database records (GreyNoise, 2026-09-21). GreyNoise's forensic timeline of that intrusion shows post-exploitation tooling (near-duplicate privilege-escalation script variants with only superficial changes between iterations, and heavy inline Chinese-language commentary explaining each attempted technique) that it assesses bears the hallmarks of LLM-assisted code generation, though no specific AI tool was identified in use (GreyNoise, 2026-09-21).

A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Zyxel PSIRT 2026-06-16

The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.

While the credentials were hashed, 564 of the victims had factory default credentials.

The adversary is the same or related to “Red Heron” reported on by Acronis based on use of the same command and control (C2) domain, malware family, exploitation of Gitea in July, and other tactics, techniques, and procedures (TTPs).

GreyNoise 2026-09-21
vulnerability22 Sep 04:32Zmulti-sourceOpen finding ↗