logo

Chinese hackers breached North American research institutions via REDCap servers

ID: 60feea69-cb6c-5adb-ab57-87a1e3bbd5e3

STIX ID: report--60feea69-cb6c-5adb-ab57-87a1e3bbd5e3

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: Sinisa Markovic

...
...

UNC6508, a China-linked APT, exploited legacy REDCap servers across North American medical research institutions (Sept 2023–Nov 2025) to deploy INFINITERED — a trojanized, modular payload that intercepts upgrades, harvests credentials via the application, and provides an HTTP-cookie backdoor; attackers later used harvested admin credentials to create a "Patroit" email compliance rule that forwarded targeted messages to a Gmail account. Google identified multiple US/Canadian victims, disrupted associated infrastructure, published IoCs/YARA rules, and advised upgrading REDCap and enforcing 2-step verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.