logo

China-Nexus Actor Spies on US Researchers Undetected for a Year

ID: 001b3f83-fc0f-530e-a212-077589dfb845

STIX ID: report--001b3f83-fc0f-530e-a212-077589dfb845

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-21

Date Updated: 2026-06-24

...
...

Google's Threat Intelligence Group disclosed a year-long China-nexus espionage campaign that harvested REDCap credentials via spear-phishing and credential-stuffing to gain persistent access to US universities and medical research institutions, quietly exfiltrating clinical and research data; Google disrupted the phishing infrastructure, shared IoCs with RedCAP administrators and US-CERT, and coordinated notifications with CISA and the FBI while recommending MFA, log reviews, network segmentation, and phishing training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.