Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Cyber Group Targets US Medical Research via REDCap

Chinese Cyber Group Targets US Medical Research via REDCap

Posted on June 16, 2026 By CWS

Google’s Threat Intelligence Group has exposed a prolonged cyber-espionage campaign orchestrated by a Chinese-linked group, targeting medical, academic, and military research entities in North America. The operation remained undetected for over a year, posing significant risks to sensitive information.

UNC6508 and Its Espionage Goals

At the core of this campaign is UNC6508, a cyber group connected to the People’s Republic of China, according to GTIG. The group’s activities align with China’s strategic interests, including national defense intelligence, military operations in the Indo-Pacific, and advancements in artificial intelligence and medical research.

The initial breach dates back to September 2023, continuing without interruption until November 2025, demonstrating a focused and sustained effort by the attackers.

Exploiting REDCap Servers

The attackers gained initial access through REDCap servers, a platform extensively used by research institutions across North America. Although GTIG could not pinpoint the exact entry vector, UNC6508 was noted for exploiting outdated and unpatched REDCap versions, a strategy known as a downgrade attack.

Once inside, the group deployed a web shell named help.php, enabling them to conduct reconnaissance and extract database credentials. Subsequently, they introduced INFINITERED, a modular malware designed to compromise legitimate REDCap files.

Impact and Defensive Measures

INFINITERED’s presence was confirmed in multiple organizations within the US and Canada. The malware includes components for credential harvesting, persistent backdoor access, and data theft. This breach allowed UNC6508 to escalate privileges and exfiltrate sensitive emails using Google’s Workspace features.

In response, GTIG and Mandiant Consulting recommend several defensive actions. These include updating REDCap installations, implementing two-step verification for admin accounts, scanning for INFINITERED using YARA rules, and auditing email compliance rules for unauthorized configurations.

Conclusion and Future Outlook

This incident highlights the ongoing threat posed by state-sponsored cyber groups. The sophisticated methods employed by UNC6508 emphasize the need for enhanced cybersecurity measures in research institutions. Continued vigilance and proactive defense strategies are essential to safeguard critical data from similar threats in the future.

Cyber Security News Tags:Chinese hackers, cyber attack, cyber defense, Cybersecurity, data breach, Espionage, espionage campaign, Google Threat Intelligence, GTIG, InfiniteRed, medical research, North America, REDCap servers, security measures, UNC6508

Post navigation

Previous Post: Cybersecurity Leaders Request Easing of AI Model Restrictions
Next Post: 94% of Cyber Incidents Involve Anonymized Networks

Related Posts

xRAT Malware Attacking Windows Users Disguised as Adult Game xRAT Malware Attacking Windows Users Disguised as Adult Game Cyber Security News
NordVPN Denies Data Breach Following Threat Actor Claim on Dark Web NordVPN Denies Data Breach Following Threat Actor Claim on Dark Web Cyber Security News
Ubiquiti UniFi Devices Vulnerability Allows Attackers to Inject Malicious Commands Ubiquiti UniFi Devices Vulnerability Allows Attackers to Inject Malicious Commands Cyber Security News
Advanced Endpoint Threat Detection in 2025 Network Environments Advanced Endpoint Threat Detection in 2025 Network Environments Cyber Security News
Cybersecurity Alert: Fake CAPTCHA Attack Endangers Enterprises Cybersecurity Alert: Fake CAPTCHA Attack Endangers Enterprises Cyber Security News
Notepad++ v8.9.3 Enhances Security and Stability Notepad++ v8.9.3 Enhances Security and Stability Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Chrome Updates Fix Over 1,400 Security Issues
  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Chrome Updates Fix Over 1,400 Security Issues
  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark