logo

Chinese hackers breach REDCap servers, steal medical research

ID: e0bb0f14-db4d-5879-b5dc-c911f92ff8fc

STIX ID: report--e0bb0f14-db4d-5879-b5dc-c911f92ff8fc

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Bill Toulas

...
...

A China-linked APT (UNC6508) targeted exposed REDCap instances at medical research organizations in North America, deploying the custom Infinitered malware (persistence/update module, credential harvester, backdoor) to capture credentials, execute commands, run SQL, and exfiltrate sensitive research. The actor abused cloud 'content compliance' email rules to automatically BCC matched data to an external account, trojanized system files to hide components, used high operational security (proxies, compromised routers, dedicated exfiltration infrastructure), and remained undetected for over a year; GTIG published YARA rules and IoCs and recommended patching REDCap, enabling MFA/DBSC, and removing legacy instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.