INFINITERED REDCap backdoor and credential harvester
Malware Activity
Summary
Hide ▲
Show ▼
The INFINITERED malware was deployed on REDCap servers to preserve access, steal credentials, and operate as a backdoor inside compromised research environments. It trojanized REDCap system files, hijacked the upgrade process so reinfected code would survive updates, and harvested usernames and passwords from the login page. The malware also accepted commands through HTTP cookies and ran on every page load, extending persistence through November 2025.
Related Happenings
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
UNC6508 China-linked REDCap espionage campaign
Campaign
H score39
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
How related:
A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email.
About this happening:
UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
UNC6508 China-linked REDCap espionage campaign
CampaignHow related: A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email.
About this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
Medical institution in North America hit by data theft breach
Incident
H score26
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
About this happening:
A North American medical institution suffered a REDCap breach that enabled InfiniteRed deployment and sensitive-data theft, leaving the network compromised for more th...
Medical institution in North America hit by data theft breach
IncidentAbout this happening: A North American medical institution suffered a REDCap breach that enabled InfiniteRed deployment and sensitive-data theft, leaving the network compromised for more th...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware Activity
H score40
First: 01.06.2026 14:00
Last: 01.06.2026 14:00
Sources 1
About this happening:
The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware ActivityAbout this happening: The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
EtherRAT Node.js backdoor with Ethereum smart-contract C2
Malware Activity
H score20
First: 26.03.2026 17:00
Last: 26.03.2026 17:00
Sources 1
About this happening:
The EtherRAT malware activity centers on a Node.js-based backdoor that uses Ethereum smart contracts to hide and rotate C2 infrastructure. In a React2Shell attack,...
EtherRAT Node.js backdoor with Ethereum smart-contract C2
Malware ActivityAbout this happening: The EtherRAT malware activity centers on a Node.js-based backdoor that uses Ethereum smart contracts to hide and rotate C2 infrastructure. In a React2Shell attack,...
Timeline
-
15.06.2026 22:44 2 articles · 1mo ago
GTIG attributes INFINITERED to UNC6508 on compromised REDCap servers
Technical Analysis UpdateGTIG attributed the INFINITERED malware to UNC6508 and described it as a trojanized backdoor on externally facing REDCap servers. The malware modified REDCap system files, hijacked the upgrade process so reinfected code would persist across versions, harvested usernames and passwords from the login page, and accepted commands through HTTP cookies. GTIG also said the campaign began with the earliest known compromise in September 2023 and continued through November 2025.
Show sources
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails — thehackernews.com — 15.06.2026 22:44
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails — thehackernews.com — 15.06.2026 22:44