---
title: "Chinese hackers breach REDCap servers, steal medical research"
url: https://daily.dev/posts/chinese-hackers-breach-redcap-servers-steal-medical-research-qlr5au8iu
source_url: https://www.bleepingcomputer.com/news/security/chinese-hackers-breach-redcap-servers-steal-medical-research
type: article
source: "BleepingComputer"
published: 2026-06-15T14:09:47.497Z
updated: 2026-06-15T14:16:40.299Z
tags: ["malware", "data-exfiltration"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Chinese hackers breach REDCap servers, steal medical research

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Google Threat Intelligence Group (GTIG) has uncovered a China-linked espionage campaign by threat actor UNC6508 that targeted exposed REDCap servers used in medical and scientific research. The attackers deployed custom malware called 'Infinitered' — consisting of a persistence module, credential harvester, and HTTP-cookie-controlled backdoor — and remained undetected for over a year (September 2023 to November 2025). A novel technique involved abusing cloud enterprise 'content compliance rules' to BCC stolen data to an attacker-controlled Gmail address. Targeted data included medical research, military topics, and geo-strategic policy. Google has notified affected organizations in the US and Canada and recommends upgrading REDCap instances, enabling MFA, and using Device Bound Session Credentials. YARA rules and IoCs are available for detection.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/chinese-hackers-breach-redcap-servers-steal-medical-research>

## Similar posts on daily.dev

- [China-linked hackers target US, Canada research using legacy REDCap exploits](https://daily.dev/posts/china-linked-hackers-target-us-canada-research-using-legacy-redcap-exploits-r3u4ofpsh) · CSO Online · 0 upvotes · 0 comments
- [A built-in Google Workspace feature became a Chinese espionage group’s favourite exfiltration tool](https://daily.dev/posts/a-built-in-google-workspace-feature-became-a-chinese-espionage-group-s-favourite-exfiltration-tool-otalaxfbi) · The Next Web · 0 upvotes · 0 comments
- [Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research](https://daily.dev/posts/public-and-private-medical-community-targeted-by-china-nexus-threat-actor-pursuing-artificial-intell-bbp2hfwem) · Google Cloud · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/chinese-hackers-breach-redcap-servers-steal-medical-research-qlr5au8iu)
