A China-linked espionage group known as UNC6508 compromised North American research and military networks by exploiting REDCap servers and abusing Google Workspace email forwarding rules to steal sensitive data.
Key Points
- The threat actor UNC6508 infiltrated clinical, academic, and military health institutions in the U.S. and Canada between September 2023 and November 2025.
- Attackers deployed custom malware called INFINITERED to hijack REDCap research servers, harvest login credentials, and establish persistent backdoors.
- Once gaining domain administrator access, the group configured Google Workspace content compliance rules to silently BCC sensitive emails to an attacker-controlled account.
- Stolen data included information on military strategy, advanced technology, AI, uncrewed vehicles, and specific medical research like the chikungunya virus.
- Google’s Threat Intelligence Group identified the campaign and has since disabled the attacker-controlled infrastructure and notified affected organizations.