Medical institution in North America hit by data theft breach
Incident
Summary
Hide ▲
Show ▼
A North American medical institution suffered a REDCap breach that enabled InfiniteRed deployment and sensitive-data theft, leaving the network compromised for more than a year. GTIG attributed the intrusion to UNC6508 and tied the initial compromise to September 2023. The attackers used a credential-harvesting component, a backdoor, and email-based exfiltration through a legitimate compliance-rule feature. Google notified affected organizations in the U.S. and Canada after identifying the activity.
Related Happenings
Google hit by network compromise
Incident
H score42
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Google hit by network compromise
IncidentAbout this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
INFINITERED REDCap backdoor and credential harvester
Malware Activity
H score26
First: 15.06.2026 22:44
Last: 15.06.2026 22:44
Sources 1
About this happening:
The INFINITERED malware was deployed on REDCap servers to preserve access, steal credentials, and operate as a backdoor inside compromised research environments. It trojan...
INFINITERED REDCap backdoor and credential harvester
Malware ActivityAbout this happening: The INFINITERED malware was deployed on REDCap servers to preserve access, steal credentials, and operate as a backdoor inside compromised research environments. It trojan...
UNC6508 China-linked REDCap espionage campaign
Campaign
H score39
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
How related:
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.
About this happening:
UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
UNC6508 China-linked REDCap espionage campaign
CampaignHow related: A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.
About this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
Timeline
-
15.06.2026 17:00 2 articles · 1mo ago
Medical institution in North America hit by data theft breach
Initial DisclosureThe intrusion appears to have started in September 2023 when attackers probed older, vulnerable REDCap versions and established access to the medical institution’s environment. The victim remained compromised without detection while the operators prepared later malware and exfiltration mechanisms.
Show sources
- Chinese hackers breach REDCap servers, steal medical research — www.bleepingcomputer.com — 15.06.2026 17:00
- Chinese hackers breach REDCap servers, steal medical research — www.bleepingcomputer.com — 15.06.2026 17:00