Acronis Uncovers Global Cyberattack Campaign Exploiting Software Flaw, Reveals New Hidden Malware

Acronis Threat Research Unit has uncovered a global cyberattack campaign in which a Chinese-speaking hacking group, tracked as Red Heron, exploited a security flaw in Gitea, a widely used code-hosting platform, to break into organizations across several countries. The attackers stole source code, harvested login credentials, and in one case gained complete administrative control over a victim’s entire server infrastructure. Acronis researchers found the attacker’s own staging server left exposed online, giving them rare visibility into how the campaign was run, including its hacking tools, target lists, and stolen data.

Within days of the Gitea flaw being publicly disclosed in July 2026, Red Heron built an automated tool that could break into vulnerable servers, steal data, and cover its tracks. The group scanned over 1,300 servers across seven countries, sorting targets by sector, including defense, elections, energy, aerospace, telecom, and government, with confirmed victims found in Canada, Argentina, Taiwan, the United States, and Sri Lanka. In one case, the attackers used a single compromised server to gain full administrative control over an entire company’s server cluster and attempted to copy complete virtual machines, making it the most extensive breach observed in the campaign.

As part of its investigation, TRU also discovered a previously unknown piece of malware, named SIXZUT, hidden inside the attacker’s toolkit. This malware can hide files, processes, and network activity from security teams, resist attempts to shut it down, and automatically restart itself if removed, making infected systems very difficult to clean. Based on the language used in the attacker’s tools and how targets were classified, TRU believes with moderate confidence that Red Heron is linked to a Chinese state-associated group, though it cannot be tied to any previously known hacking group at this time.

Author