Chinese hackers breach REDCap servers, steal medical research

A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.

BleepingComputer

A new report reveals how Chinese state-sponsored hackers, UNC6508, maintained deep access to North American medical research institutions for over a year, stealing critical data. Their most insidious tactic? Abusing a legitimate cloud "Patriot" rule to automatically exfiltrate intelligence via email, blending seamlessly with normal traffic and bypassing standard security.

https://www.tpp.blog/1q7todf

#cybersecurity #unc6508 #redcap

🤖 This post was AI-generated.

#China's hackers breach #REDCap servers, steal #medical research
The REDCap platform is widely used in medical and scientific research to build and manage databases and surveys that comply with regulations for medical and scientific research.
Based on the investigation, the compromise of the #medicalresearch organization occurred in September 2023, and the malicious activity continued for more than a year through November 2025.
https://www.bleepingcomputer.com/news/security/chinese-hackers-breach-redcap-servers-steal-medical-research/
Chinese hackers breach REDCap servers, steal medical research

A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.

BleepingComputer

Chinese Hackers Exploit Google Workspace to Siphon Research and Defense Emails

Chinese hackers have been secretly siphoning off sensitive emails from research and defense organizations using a clever exploit of Google Workspace, with a long-running campaign that spanned over two years. The threat actors, tracked as UNC6508, used custom malware called INFINITERED to breach externally facing servers and steal…

https://osintsights.com/chinese-hackers-exploit-google-workspace-to-siphon-research-and-defense-emails?utm_source=mastodon&utm_medium=social

#China #GoogleWorkspace #Unc6508 #Infinitered #Redcap

Chinese Hackers Exploit Google Workspace to Siphon Research and Defense Emails

Learn how Chinese hackers exploit Google Workspace to steal research and defense emails, and take action now to protect your organization from UNC6508 threats.

OSINTSights

China-linked UNC6508 Targets Medical Research Institutions

A sophisticated cyber threat group linked to China, known as UNC6508, has launched a targeted attack on medical research institutions in North America, exploiting vulnerabilities in REDCap servers to gain a foothold. The intrusions, which began in September 2023, aim to compromise sensitive research data.

https://osintsights.com/china-linked-unc6508-targets-medical-research-institutions?utm_source=mastodon&utm_medium=social

#ChinalinkedUnc6508 #MedicalResearch #Redcap #Infinitered #NationState

China-linked UNC6508 Targets Medical Research Institutions

Learn how China-linked UNC6508 targets medical research institutions and take steps to protect your organization from sophisticated cyber threats now.

OSINTSights
02/13/2026
The Nisse and Tomte are cute little gnomes. Then there’s the Red Caps.
https://thedevilspanties.com/archives/16946
Check out our Store: https://store.thedevilspanties.com
#webcomic,#webtoon,#comicstrip,#indiecomics,#knitting,#Nisse,#Nisselue,#protest,#RedCap,#resistance,#Tomte
02/13/2026
The Nisse and Tomte are cute little gnomes. Then there’s the Red Caps.
https://thedevilspanties.com/archives/16946
Check out our Store: https://store.thedevilspanties.com
#knitting,#Nisse,#Nisselue,#protest,#RedCap,#resistance,#Tomte