Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Cyber Group Targets US Medical Research via REDCap

Chinese Cyber Group Targets US Medical Research via REDCap

Posted on June 16, 2026 By CWS

Google’s Threat Intelligence Group has exposed a prolonged cyber-espionage campaign orchestrated by a Chinese-linked group, targeting medical, academic, and military research entities in North America. The operation remained undetected for over a year, posing significant risks to sensitive information.

UNC6508 and Its Espionage Goals

At the core of this campaign is UNC6508, a cyber group connected to the People’s Republic of China, according to GTIG. The group’s activities align with China’s strategic interests, including national defense intelligence, military operations in the Indo-Pacific, and advancements in artificial intelligence and medical research.

The initial breach dates back to September 2023, continuing without interruption until November 2025, demonstrating a focused and sustained effort by the attackers.

Exploiting REDCap Servers

The attackers gained initial access through REDCap servers, a platform extensively used by research institutions across North America. Although GTIG could not pinpoint the exact entry vector, UNC6508 was noted for exploiting outdated and unpatched REDCap versions, a strategy known as a downgrade attack.

Once inside, the group deployed a web shell named help.php, enabling them to conduct reconnaissance and extract database credentials. Subsequently, they introduced INFINITERED, a modular malware designed to compromise legitimate REDCap files.

Impact and Defensive Measures

INFINITERED’s presence was confirmed in multiple organizations within the US and Canada. The malware includes components for credential harvesting, persistent backdoor access, and data theft. This breach allowed UNC6508 to escalate privileges and exfiltrate sensitive emails using Google’s Workspace features.

In response, GTIG and Mandiant Consulting recommend several defensive actions. These include updating REDCap installations, implementing two-step verification for admin accounts, scanning for INFINITERED using YARA rules, and auditing email compliance rules for unauthorized configurations.

Conclusion and Future Outlook

This incident highlights the ongoing threat posed by state-sponsored cyber groups. The sophisticated methods employed by UNC6508 emphasize the need for enhanced cybersecurity measures in research institutions. Continued vigilance and proactive defense strategies are essential to safeguard critical data from similar threats in the future.

Cyber Security News Tags:Chinese hackers, cyber attack, cyber defense, Cybersecurity, data breach, Espionage, espionage campaign, Google Threat Intelligence, GTIG, InfiniteRed, medical research, North America, REDCap servers, security measures, UNC6508

Post navigation

Previous Post: Cybersecurity Leaders Request Easing of AI Model Restrictions
Next Post: 94% of Cyber Incidents Involve Anonymized Networks

Related Posts

Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details Cyber Security News
48M Gmail, 6.5M Instagram Exposed Online From Unprotected Database 48M Gmail, 6.5M Instagram Exposed Online From Unprotected Database Cyber Security News
Russian Hackers Spoof European Events in Targeted Phishing Attacks Russian Hackers Spoof European Events in Targeted Phishing Attacks Cyber Security News
AI-Driven Code Attack Targets Crypto Projects AI-Driven Code Attack Targets Crypto Projects Cyber Security News
Sophisticated DevilsTongue Windows Spyware Tracking Users Globally Sophisticated DevilsTongue Windows Spyware Tracking Users Globally Cyber Security News
Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Novo Nordisk Data Breach: Cybercrime Group Claims Responsibility
  • SprySOCKS Backdoor Expands to Windows with New Variants
  • AI Enhances Russian and Chinese Influence Tactics
  • White House Enhances Cybersecurity for National Security Systems
  • 94% of Cyber Incidents Involve Anonymized Networks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Novo Nordisk Data Breach: Cybercrime Group Claims Responsibility
  • SprySOCKS Backdoor Expands to Windows with New Variants
  • AI Enhances Russian and Chinese Influence Tactics
  • White House Enhances Cybersecurity for National Security Systems
  • 94% of Cyber Incidents Involve Anonymized Networks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark