Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
ID: cb95cb89-0fdb-5d85-9e79-61849a962bf8
STIX ID: report--cb95cb89-0fdb-5d85-9e79-61849a962bf8
Feed Name: The Hacker News
Google's Threat Intelligence Group attributes a long-running China-linked espionage campaign (UNC6508) to a backdoored REDCap web platform (INFINITERED) that harvested credentials, persisted through upgrades, and enabled lateral movement to domain admin accounts; the attackers then abused Google Workspace content compliance rules to silently exfiltrate nearly 150 types of sensitive email (research, military, policy) to an attacker-controlled Gmail, affecting multiple US and Canadian clinical, academic, and military health organizations and prompting remediation guidance (patch/remove vulnerable REDCap versions, audit mail rules, apply phishing-resistant MFA).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
