Chinese Hackers Breach REDCap Servers, Steal Medical Research Data
ID: 712212b8-5681-516f-ab3d-8be7c6b82f03
STIX ID: report--712212b8-5681-516f-ab3d-8be7c6b82f03
Feed Name: CosmicBytez Labs
A China-linked APT campaign has been observed exploiting internet-exposed REDCap servers to install a novel implant named "InfiniteRed" and steal clinical and biomedical research data. The report outlines the attack chain (initial access via exposed REDCap, malware deployment, data collection, and covert exfiltration), attributes the activity to state-linked actors consistent with prior healthcare targeting, notes at least one North American institution impacted, and provides mitigation and reporting guidance for REDCap administrators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
