Google says Chinese hackers cracked Workspace security to target “a diverse set of national, state and private medical entities,” including research and defense organizations


  • Google GTIG Uncovers UNC6508, a PRC-Linked Group Exploiting REDCap Servers with Custom INFINITERED Malware
  • Attackers stole credentials, exfiltrated sensitive data via rigged compliance rules and hid for over a year
  • Gmail accounts linked to campaign disabled; administrators are encouraged to enforce phishing-resistant MFA, device-bound sessions, and advanced protection

For more than a year, Chinese state-sponsored threat actors have been lurking on the servers of North American academic, medical and military research organizations, deploying custom malware and exfiltrating sensitive files, experts have warned.

The Google Threat Intelligence Group (GTIG) published a new report detailing the recent works of UNC6508, a threat actor in the People’s Republic of China (PRC), who allegedly managed to exploit externally facing Research Electronic Data Capture (REDCap) servers to deploy a custom piece of malware called INFINITERED.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top