UNC6508 China-linked REDCap espionage campaign
Campaign
Summary
Hide ▲
Show ▼
UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operation persisted from September 2023 through November 2025, giving the actor more than a year of access, and combined credential theft with Google Workspace content compliance rules abuse to quietly BCC sensitive research and defense email to an attacker-controlled inbox. Google said it attributed the activity with high confidence, notified affected organizations, and disrupted the group's infrastructure.
Related Happenings
Google hit by network compromise
Incident
H score42
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Google hit by network compromise
IncidentAbout this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
INFINITERED REDCap backdoor and credential harvester
Malware Activity
H score26
First: 15.06.2026 22:44
Last: 15.06.2026 22:44
Sources 1
How related:
Around three months after getting in, the group deployed custom malware GTIG calls INFINITERED, which trojanizes REDCap's own system files and does three things.
About this happening:
The INFINITERED malware was deployed on REDCap servers to preserve access, steal credentials, and operate as a backdoor inside compromised research environments. It trojan...
INFINITERED REDCap backdoor and credential harvester
Malware ActivityHow related: Around three months after getting in, the group deployed custom malware GTIG calls INFINITERED, which trojanizes REDCap's own system files and does three things.
About this happening: The INFINITERED malware was deployed on REDCap servers to preserve access, steal credentials, and operate as a backdoor inside compromised research environments. It trojan...
Medical institution in North America hit by data theft breach
Incident
H score26
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
How related:
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.
About this happening:
A North American medical institution suffered a REDCap breach that enabled InfiniteRed deployment and sensitive-data theft, leaving the network compromised for more th...
Medical institution in North America hit by data theft breach
IncidentHow related: A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.
About this happening: A North American medical institution suffered a REDCap breach that enabled InfiniteRed deployment and sensitive-data theft, leaving the network compromised for more th...
SHADOW-EARTH-053 China-aligned espionage campaign against Asian government and defense targets
Campaign
H score39
First: 01.05.2026 17:02
Last: 01.05.2026 17:02
Sources 1
About this happening:
SHADOW-EARTH-053 is running an active China-aligned espionage campaign against government and defense targets across South, East, and Southeast Asia and Poland...
SHADOW-EARTH-053 China-aligned espionage campaign against Asian government and defense targets
CampaignAbout this happening: SHADOW-EARTH-053 is running an active China-aligned espionage campaign against government and defense targets across South, East, and Southeast Asia and Poland...
North Korean remote IT worker scam operation targeting American companies
Campaign
H score41
First: 16.04.2026 19:00
Last: 16.04.2026 19:00
Sources 1
About this happening:
A long-running North Korean remote IT worker scam operation used stolen identities and fake placements to embed operators inside more than 100 American companies. The...
North Korean remote IT worker scam operation targeting American companies
CampaignAbout this happening: A long-running North Korean remote IT worker scam operation used stolen identities and fake placements to embed operators inside more than 100 American companies. The...
Timeline
-
15.06.2026 17:00 3 articles · 1mo ago
UNC6508 targets exposed REDCap servers to steal medical research data
Initial DisclosureGTIG disclosed a China-linked espionage campaign in which UNC6508 targeted exposed REDCap servers at a North American medical institution, deployed the InfiniteRed malware, and stole sensitive research data. The investigation tied the compromise to September 2023, noted malicious activity continuing through November 2025, and observed email-based exfiltration through a legitimate content compliance rules feature.
Show sources
- Chinese hackers breach REDCap servers, steal medical research — www.bleepingcomputer.com — 15.06.2026 17:00
- Chinese hackers breach REDCap servers, steal medical research — www.bleepingcomputer.com — 15.06.2026 17:00
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails — thehackernews.com — 15.06.2026 22:44