BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked Spy Group Hits North American Research

UNC6508 group stole US military, AI, and medical research via backdoored servers.

  • A China-linked espionage group, UNC6508, secretly infiltrated North American research networks for over a year.
  • The attackers used a backdoor called INFINITERED to compromise REDCap servers and steal login credentials.
  • They exfiltrated sensitive emails by abusing Google Workspace’s own content compliance rules, copying messages to a secret inbox.
  • The stolen data focused on military, AI, and medical research, including specific terms like chikungunya.
  • Google’s Threat Intelligence Group reported the campaign and disrupted the infrastructure.

A China-linked espionage group compromised medical, academic, and military research networks across the US and Canada for more than a year. Google’s Threat Intelligence Group detailed this campaign in a new report, attributing it to a cluster tracked as UNC6508.

- Advertisement -

The attackers first breached externally facing REDCap servers, possibly targeting older, vulnerable versions. Consequently, they deployed custom malware that hijacked the server’s upgrade process to maintain persistence.

This malware, named INFINITERED, secretly harvested usernames and passwords from the login page. It then acted as a backdoor, accepting commands through HTTP cookies on every page load.

After moving laterally with stolen credentials, the group gained domain administrator access. They then weaponized a legitimate Google Workspace feature to steal email without detection.

UNC6508 created a content compliance rule that monitored for nearly 150 specific keywords. Whenever a matching email was sent, the system automatically BCC’d a copy to an attacker-controlled Gmail address.

- Advertisement -

The targeted search terms revealed a focus on geo-strategic policy and advanced technology. One notably specific keyword was chikungunya, a virus behind a 2025 outbreak in China.

Google recommends patching all external REDCap servers and removing old versions entirely. Organizations must also audit their cloud mail rules for any unauthorized forwarding instructions.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

UFC Fighters Paid Bonuses in Trump-Linked Stablecoin

Fighters at the UFC event on the White House lawn received up to $250,000...

Judge Dismisses xAI Trade Secret Lawsuit Against OpenAI

A federal judge dismissed xAI's trade secret lawsuit against OpenAI without allowing it to...

Ethereum hosts most of Ripple’s RLUSD stablecoin

Over half ($879 million) of Ripple's RLUSD stablecoin supply is hosted on Ethereum, not...

CFTC Hires Blockchain Forensics Chief as Tech Focus Grows

The CFTC appointed a blockchain forensics expert as its new chief data innovation officer,...

Microsoft 365 SearchLeak Bug Exposed Data in One Click

A one-click exploit called SearchLeak could exfiltrate emails, calendar details, and indexed files from...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading