Chinese hackers breached North American research institutions via REDCap servers
ID: 60feea69-cb6c-5adb-ab57-87a1e3bbd5e3
STIX ID: report--60feea69-cb6c-5adb-ab57-87a1e3bbd5e3
Feed Name: Help Net Security
UNC6508, a China-linked APT, exploited legacy REDCap servers across North American medical research institutions (Sept 2023–Nov 2025) to deploy INFINITERED — a trojanized, modular payload that intercepts upgrades, harvests credentials via the application, and provides an HTTP-cookie backdoor; attackers later used harvested admin credentials to create a "Patroit" email compliance rule that forwarded targeted messages to a Gmail account. Google identified multiple US/Canadian victims, disrupted associated infrastructure, published IoCs/YARA rules, and advised upgrading REDCap and enforcing 2-step verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
