REDCap on the Internet: An Exposure Analysis
ID: 78bc4060-1351-5a75-8ab8-b853b0208d50
STIX ID: report--78bc4060-1351-5a75-8ab8-b853b0208d50
Feed Name: Censys Blog
**Executive Summary:** Google Threat Intelligence Group attributed a year-plus espionage campaign to PRC-nexus actor UNC6508 that exploited public-facing REDCap servers to install a PHP backdoor called INFINITERED, maintain persistent access, and exfiltrate sensitive academic, medical, and military research data; Censys provides exposure metrics (≈8,500 instances, 40% U.S.), common REDCap versions observed, affected networks, and mitigation guidance including patching, inventorying instances, and enforcing MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
