PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research
Key Takeaways A Chinese state-sponsored cyberespionage group, UNC6508, targeted North American medical, academic, and military research organizations for over a year. The attackers exploited REDCap...
Key Takeaways
- A Chinese state-sponsored cyberespionage group, UNC6508, targeted North American medical, academic, and military research organizations for over a year.
- The attackers exploited REDCap servers, a widely used research platform, to deploy sophisticated malware named INFINITERED.
- UNC6508 exfiltrated sensitive data by abusing Google Workspace’s content compliance rules to forward emails containing specific keywords to an attacker-controlled Gmail account.
- Google’s Threat Intelligence Group (GTIG) has disrupted the campaign’s infrastructure and provided mitigation recommendations.
Google’s Threat Intelligence Group (GTIG) has exposed a persistent cyberespionage campaign orchestrated by a Chinese state-sponsored actor, UNC6508. This sophisticated operation, which remained undetected for over a year, specifically targeted institutions in North America involved in medical, academic, and military research.
Table Of Content
GTIG confidently attributes this campaign to UNC6508, a threat actor with clear ties to the People’s Republic of China (PRC) and motivations consistent with state-sponsored espionage. The group’s intelligence collection priorities—spanning national defense, Indo-Pacific military operations, artificial intelligence, uncrewed vehicle systems, offensive cyber capabilities, and medical research—align directly with China’s strategic national interests.
Evidence suggests the campaign began as early as September 2023 and continued actively through November 2025, indicating a long-term, sustained effort to gather intelligence.
PRC-Nexus Hackers Exploit REDCap Servers
The initial entry point for UNC6508’s campaign involved externally accessible REDCap (Research Electronic Data Capture) servers. REDCap is a ubiquitous web-based platform critical to medical and scientific research communities across North America.
While the precise initial access vector could not be definitively confirmed by GTIG, observations revealed UNC6508 actively scanning for and exploiting legacy, unpatched REDCap versions co-existing with more current installations. This tactic is characteristic of a downgrade attack, as defined by MITRE ATT&CK T1689.
Once initial access was secured, the threat actor deployed a web shell, identified as help.php. Following this, UNC6508 conducted internal network reconnaissance and proceeded to harvest credentials for database and service accounts.
Approximately three months after the initial compromise, UNC6508 escalated its activities by deploying INFINITERED. This advanced, modular malware is designed to trojanize legitimate REDCap system files, ensuring stealth and persistence within compromised environments.
INFINITERED operates through three primary components:
- Dropper/Upgrade Interceptor: This component injects malicious code into new REDCap upgrade packages. It ensures the malware’s persistence even after software updates by utilizing a hardcoded GUID delimiter (
b49e334d-9c01-463e-9bc5-00a6920fb66e). - Credential Harvester: Designed to capture plaintext usernames and passwords from POST login requests, this module encrypts the stolen credentials and covertly stores them within the REDCap sessions database, prefixed with
xc32038474a. - Backdoor with C2: This backdoor activates with every REDCap page load, specifically listening for an HTTP Cookie parameter named
REDCAP-TOKEN. It supports a range of malicious commands, including remote shell execution, SQL queries, file upload/download capabilities, and system beaconing.
INFINITERED was detected across numerous organizations in both the United States and Canada. After maintaining silent access for over a year, UNC6508 escalated its privileges, leveraging harvested credentials to gain access to a domain administrator account.
The group then exploited a legitimate Google Workspace feature: content compliance rules. They configured a rule to silently BCC-forward sensitive emails to an attacker-controlled Gmail account, BebitaBarefoot774[@]gmail[.]com. The rule, notably misspelled as “Patroit,” employed regular expressions to match nearly 150 keywords related to military strategy, AI research, cyber programs, and medical subjects.
GTIG highlighted that this specific technique—abusing domain content compliance rules for data exfiltration—had not been previously observed in campaigns attributed to PRC-nexus actors. A particularly telling keyword discovered in the rule was “Chikungunya,” the mosquito-borne virus responsible for an outbreak in China’s Guangdong province in July 2025. This suggests real-time, mission-specific intelligence tasking guided the attackers’ data collection.
To mask their activities and complicate attribution, UNC6508 utilized US-based obfuscation (OBF) networks. This involved routing traffic through compromised ASUS routers, residential proxies, and virtual private server (VPS) infrastructure.
What You Should Do
Upon discovering the campaign, GTIG took immediate action, disrupting the malicious infrastructure and deactivating the Gmail exfiltration account. GTIG and Mandiant Consulting strongly recommend the following immediate mitigation steps for affected organizations and defenders:
- Patch all REDCap installations to the latest available version and ensure the complete removal of any legacy or outdated installations.
- Implement and enforce phishing-resistant 2-Step Verification (2SV) for all administrator accounts across your environment.
- Scan REDCap servers for the INFINITERED malware using the published YARA rules provided by GTIG.
- Conduct a thorough audit of all content compliance rules within your cloud mail suites to identify any unauthorized or suspicious BCC-forwarding configurations.
- Deploy Device Bound Session Credentials (DBSC) to enhance security against session cookie theft.
- Enable robust Data Loss Prevention (DLP) rules and comprehensive Security Information and Event Management (SIEM) logging to detect anomalous data movement and unauthorized email forwarding activities.
GTIG has updated Google Security Operations (SecOps) with all relevant Indicators of Compromise (IOCs) and has directly notified all organizations confirmed to be affected by this campaign.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.