AUTO-UPDATED

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

A China-linked espionage group known as UNC6508 compromised North American research and military networks by exploiting REDCap servers and abusing Google Workspace email forwarding rules to steal sensitive data.

Key Points

  • The threat actor UNC6508 infiltrated clinical, academic, and military health institutions in the U.S. and Canada between September 2023 and November 2025.
  • Attackers deployed custom malware called INFINITERED to hijack REDCap research servers, harvest login credentials, and establish persistent backdoors.
  • Once gaining domain administrator access, the group configured Google Workspace content compliance rules to silently BCC sensitive emails to an attacker-controlled account.
  • Stolen data included information on military strategy, advanced technology, AI, uncrewed vehicles, and specific medical research like the chikungunya virus.
  • Google’s Threat Intelligence Group identified the campaign and has since disabled the attacker-controlled infrastructure and notified affected organizations.

Why it Matters

This campaign demonstrates how sophisticated actors can weaponize legitimate administrative features in cloud environments to exfiltrate data without triggering traditional security alerts. Organizations must prioritize auditing mail-forwarding rules and securing administrator accounts with phishing-resistant multi-factor authentication to prevent similar unauthorized data access.
Internet Published by info@thehackernews.com (The Hacker News)
Read original