logo

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

ID: cb95cb89-0fdb-5d85-9e79-61849a962bf8

STIX ID: report--cb95cb89-0fdb-5d85-9e79-61849a962bf8

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

Google's Threat Intelligence Group attributes a long-running China-linked espionage campaign (UNC6508) to a backdoored REDCap web platform (INFINITERED) that harvested credentials, persisted through upgrades, and enabled lateral movement to domain admin accounts; the attackers then abused Google Workspace content compliance rules to silently exfiltrate nearly 150 types of sensitive email (research, military, policy) to an attacker-controlled Gmail, affecting multiple US and Canadian clinical, academic, and military health organizations and prompting remediation guidance (patch/remove vulnerable REDCap versions, audit mail rules, apply phishing-resistant MFA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.