China-Linked Hackers Targeted Medical and Military Research Through REDCap in Long-Running Attack
ID: c34a94b6-e2b6-5161-bea9-93ce020dcc31
STIX ID: report--c34a94b6-e2b6-5161-bea9-93ce020dcc31
Feed Name: Security Boulevard
Threat Score
**Executive summary:** Google TAG reported a long-running, China-linked espionage campaign (UNC6508) that compromised externally facing REDCap instances to deploy custom malware (INFINITERED), capture credentials and maintain persistence with web shells, then abused Google Workspace content compliance rules to silently exfiltrate targeted emails from North American academic, medical, and military research organizations—activity that remained undetected for over a year.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
