Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ClamAV Vulnerabilities Let Attackers Trigger DoS
August 11, 2026
Phishing Attack Uses SSL/TLS Certificates to Target WhatsApp Users
August 11, 2026
OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting
August 11, 2026
Home/CyberSecurity News/PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research
CyberSecurity News

PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research

Key Takeaways A Chinese state-sponsored cyberespionage group, UNC6508, targeted North American medical, academic, and military research organizations for over a year. The attackers exploited REDCap...

David kimber
David kimber
June 16, 2026 4 Min Read
56 0

Key Takeaways

  • A Chinese state-sponsored cyberespionage group, UNC6508, targeted North American medical, academic, and military research organizations for over a year.
  • The attackers exploited REDCap servers, a widely used research platform, to deploy sophisticated malware named INFINITERED.
  • UNC6508 exfiltrated sensitive data by abusing Google Workspace’s content compliance rules to forward emails containing specific keywords to an attacker-controlled Gmail account.
  • Google’s Threat Intelligence Group (GTIG) has disrupted the campaign’s infrastructure and provided mitigation recommendations.

Google’s Threat Intelligence Group (GTIG) has exposed a persistent cyberespionage campaign orchestrated by a Chinese state-sponsored actor, UNC6508. This sophisticated operation, which remained undetected for over a year, specifically targeted institutions in North America involved in medical, academic, and military research.

Table Of Content

  • Key Takeaways
  • PRC-Nexus Hackers Exploit REDCap Servers
  • What You Should Do

GTIG confidently attributes this campaign to UNC6508, a threat actor with clear ties to the People’s Republic of China (PRC) and motivations consistent with state-sponsored espionage. The group’s intelligence collection priorities—spanning national defense, Indo-Pacific military operations, artificial intelligence, uncrewed vehicle systems, offensive cyber capabilities, and medical research—align directly with China’s strategic national interests.

Evidence suggests the campaign began as early as September 2023 and continued actively through November 2025, indicating a long-term, sustained effort to gather intelligence.

PRC-Nexus Hackers Exploit REDCap Servers

The initial entry point for UNC6508’s campaign involved externally accessible REDCap (Research Electronic Data Capture) servers. REDCap is a ubiquitous web-based platform critical to medical and scientific research communities across North America.

While the precise initial access vector could not be definitively confirmed by GTIG, observations revealed UNC6508 actively scanning for and exploiting legacy, unpatched REDCap versions co-existing with more current installations. This tactic is characteristic of a downgrade attack, as defined by MITRE ATT&CK T1689.

Once initial access was secured, the threat actor deployed a web shell, identified as help.php. Following this, UNC6508 conducted internal network reconnaissance and proceeded to harvest credentials for database and service accounts.

Approximately three months after the initial compromise, UNC6508 escalated its activities by deploying INFINITERED. This advanced, modular malware is designed to trojanize legitimate REDCap system files, ensuring stealth and persistence within compromised environments.

INFINITERED operates through three primary components:

  • Dropper/Upgrade Interceptor: This component injects malicious code into new REDCap upgrade packages. It ensures the malware’s persistence even after software updates by utilizing a hardcoded GUID delimiter (b49e334d-9c01-463e-9bc5-00a6920fb66e).
  • Credential Harvester: Designed to capture plaintext usernames and passwords from POST login requests, this module encrypts the stolen credentials and covertly stores them within the REDCap sessions database, prefixed with xc32038474a.
  • Backdoor with C2: This backdoor activates with every REDCap page load, specifically listening for an HTTP Cookie parameter named REDCAP-TOKEN. It supports a range of malicious commands, including remote shell execution, SQL queries, file upload/download capabilities, and system beaconing.

INFINITERED was detected across numerous organizations in both the United States and Canada. After maintaining silent access for over a year, UNC6508 escalated its privileges, leveraging harvested credentials to gain access to a domain administrator account.

The group then exploited a legitimate Google Workspace feature: content compliance rules. They configured a rule to silently BCC-forward sensitive emails to an attacker-controlled Gmail account, BebitaBarefoot774[@]gmail[.]com. The rule, notably misspelled as “Patroit,” employed regular expressions to match nearly 150 keywords related to military strategy, AI research, cyber programs, and medical subjects.

GTIG highlighted that this specific technique—abusing domain content compliance rules for data exfiltration—had not been previously observed in campaigns attributed to PRC-nexus actors. A particularly telling keyword discovered in the rule was “Chikungunya,” the mosquito-borne virus responsible for an outbreak in China’s Guangdong province in July 2025. This suggests real-time, mission-specific intelligence tasking guided the attackers’ data collection.

To mask their activities and complicate attribution, UNC6508 utilized US-based obfuscation (OBF) networks. This involved routing traffic through compromised ASUS routers, residential proxies, and virtual private server (VPS) infrastructure.

What You Should Do

Upon discovering the campaign, GTIG took immediate action, disrupting the malicious infrastructure and deactivating the Gmail exfiltration account. GTIG and Mandiant Consulting strongly recommend the following immediate mitigation steps for affected organizations and defenders:

  • Patch all REDCap installations to the latest available version and ensure the complete removal of any legacy or outdated installations.
  • Implement and enforce phishing-resistant 2-Step Verification (2SV) for all administrator accounts across your environment.
  • Scan REDCap servers for the INFINITERED malware using the published YARA rules provided by GTIG.
  • Conduct a thorough audit of all content compliance rules within your cloud mail suites to identify any unauthorized or suspicious BCC-forwarding configurations.
  • Deploy Device Bound Session Credentials (DBSC) to enhance security against session cookie theft.
  • Enable robust Data Loss Prevention (DLP) rules and comprehensive Security Information and Event Management (SIEM) logging to detect anomalous data movement and unauthorized email forwarding activities.

GTIG has updated Google Security Operations (SecOps) with all relevant Indicators of Compromise (IOCs) and has directly notified all organizations confirmed to be affected by this campaign.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarePatchphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Infinite Campus Data Breach Exposes 137,000 Users’ Personal Data

Next Post

Microsoft Teams Exposes Wi-Fi Hotspot Data on Employee Devices

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Critical HP ThinPro TPM Flaw Exposes LUKS Disk Encryption Keys
August 10, 2026
Critical Windows WalletService Bug (CVE-2024-XXXX) Lets Attackers Escalate Privileges
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us