Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Cyber Group Exploits Google Workspace to Steal Emails

Chinese Cyber Group Exploits Google Workspace to Steal Emails

Posted on June 15, 2026 By CWS

A cyber espionage group linked to China infiltrated North American medical, academic, and defense research networks, extracting sensitive information over a prolonged period. This breach involved manipulating Google Workspace settings to divert important emails to accounts under their control.

Infiltration of Research Networks

Hackers accessed these networks through a vulnerability in REDCap servers, which are typically used by hospitals and universities to manage research data. By compromising these servers, the group, identified as UNC6508 by Google’s Threat Intelligence Group (GTIG), acquired login credentials, allowing them to embed themselves within the network.

Google’s report, released recently, connects UNC6508 with previous cyber activities against the defense sector. Although the specific organizations affected were not named, they encompass clinical, academic, and military health entities across the United States and Canada. Google has taken steps to alert these organizations and dismantle the cyber group’s infrastructure.

Methods of Entry and Malware Deployment

REDCap, a data management platform, served as the entry point for UNC6508. The cyber group exploited vulnerabilities in externally accessible REDCap servers. While the exact method of initial access remains unclear, probes into older software versions were observed.

Several months post-compromise, custom malware, dubbed INFINITERED, was introduced. This malware modified REDCap’s system files, ensuring persistence by reapplying itself during software upgrades. It also captured login details and served as a backdoor, receiving commands via cookies.

The group’s activities date back to at least September 2023, continuing until November 2025. Once inside the servers, the attackers conducted reconnaissance, obtained credentials, and escalated privileges to access domain administrator accounts.

Exploitation of Google Workspace Rules

UNC6508 leveraged Google Workspace’s content compliance features to steal emails. This legitimate tool was manipulated to forward messages containing specific keywords to an external Gmail account controlled by the attackers. Google has since disabled this account.

The keywords targeted sensitive areas such as strategic policies, military equipment, advanced technologies, and medical research, highlighting the group’s priorities. The use of domain content compliance rules for such purposes had not been previously observed in China-linked attacks, according to GTIG.

Recommendations for Defense

Organizations should start by securing their REDCap servers, updating software, and eliminating outdated versions to prevent similar breaches. On the email front, it’s crucial to review and audit content compliance and mail-forwarding settings to ensure no unauthorized rerouting of emails. Implementing multi-factor authentication for administrator accounts can also mitigate risks, as admin access was pivotal in this attack.

While the exact method of initial access to REDCap servers remains unknown, scrutinizing mail rule changes is vital. Once attackers gain admin privileges, legitimate cloud features can be repurposed for data exfiltration, highlighting the need for comprehensive security audits.

The Hacker News Tags:admin access, Chinese hackers, Cybersecurity, email theft, Google Threat Intelligence, Google Workspace, Malware, Phishing, REDCap servers, UNC6508

Post navigation

Previous Post: Microsoft 365 Copilot Flaw Allows Data Theft in One Click
Next Post: NarwhalRAT Malware Targets Korean Users via LNK Files

Related Posts

Security Flaw in Vertex AI Risks Google Cloud Data Security Flaw in Vertex AI Risks Google Cloud Data The Hacker News
Credential-Stealing Attack Hits SAP npm Packages Credential-Stealing Attack Hits SAP npm Packages The Hacker News
SourTrade Campaign Uses Malvertising for Malware Assembly SourTrade Campaign Uses Malvertising for Malware Assembly The Hacker News
Anthropic AI Vulnerability Risks macOS File Access Anthropic AI Vulnerability Risks macOS File Access The Hacker News
Critical Flaws in Joomla Extensions Exploited in Zero-Day Attacks Critical Flaws in Joomla Extensions Exploited in Zero-Day Attacks The Hacker News
Deepfakes. Fake Recruiters. Cloned CFOs — Learn How to Stop AI-Driven Attacks in Real Time Deepfakes. Fake Recruiters. Cloned CFOs — Learn How to Stop AI-Driven Attacks in Real Time The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Warns Water Sector of Rising Cyber Threats
  • Bank of America to Acquire UK Cybersecurity Leader
  • Chrome 151 Update Fixes Critical Security Vulnerabilities
  • Okta Expands Security with Permiso Acquisition
  • North Korean macOS Scam Uses Fake Updates to Steal Crypto

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Warns Water Sector of Rising Cyber Threats
  • Bank of America to Acquire UK Cybersecurity Leader
  • Chrome 151 Update Fixes Critical Security Vulnerabilities
  • Okta Expands Security with Permiso Acquisition
  • North Korean macOS Scam Uses Fake Updates to Steal Crypto

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark