PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data
ID: 78c40eec-35bd-55e1-b191-589ba60a06c5
STIX ID: report--78c40eec-35bd-55e1-b191-589ba60a06c5
Feed Name: The Register (Security)
Chinese state-linked APT UNC6508 compromised externally facing REDCap servers at multiple North American medical and military research institutions (first observed in Sept 2023), deployed modular custom malware named InfiniteRed to harvest credentials and persist, and created Google Workspace content compliance rules (misnamed "Patroit") to BCC sensitive emails (defense, advanced tech, and medical research) to an attacker-controlled Gmail account; Google Threat Intelligence Group discovered the campaign, disabled the exfiltration account, and notified victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
