Google Threat Intelligence Group (GTIG) has uncovered a China-linked espionage campaign by threat actor UNC6508 that targeted exposed REDCap servers used in medical and scientific research. The attackers deployed custom malware called 'Infinitered' — consisting of a persistence module, credential harvester, and HTTP-cookie-controlled backdoor — and remained undetected for over a year (September 2023 to November 2025). A novel technique involved abusing cloud enterprise 'content compliance rules' to BCC stolen data to an attacker-controlled Gmail address. Targeted data included medical research, military topics, and geo-strategic policy. Google has notified affected organizations in the US and Canada and recommends upgrading REDCap instances, enabling MFA, and using Device Bound Session Credentials. YARA rules and IoCs are available for detection.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
45 Impressions