Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Cyber Group Targets US Medical Research via REDCap

Chinese Cyber Group Targets US Medical Research via REDCap

Posted on June 16, 2026 By CWS

Google’s Threat Intelligence Group has exposed a prolonged cyber-espionage campaign orchestrated by a Chinese-linked group, targeting medical, academic, and military research entities in North America. The operation remained undetected for over a year, posing significant risks to sensitive information.

UNC6508 and Its Espionage Goals

At the core of this campaign is UNC6508, a cyber group connected to the People’s Republic of China, according to GTIG. The group’s activities align with China’s strategic interests, including national defense intelligence, military operations in the Indo-Pacific, and advancements in artificial intelligence and medical research.

The initial breach dates back to September 2023, continuing without interruption until November 2025, demonstrating a focused and sustained effort by the attackers.

Exploiting REDCap Servers

The attackers gained initial access through REDCap servers, a platform extensively used by research institutions across North America. Although GTIG could not pinpoint the exact entry vector, UNC6508 was noted for exploiting outdated and unpatched REDCap versions, a strategy known as a downgrade attack.

Once inside, the group deployed a web shell named help.php, enabling them to conduct reconnaissance and extract database credentials. Subsequently, they introduced INFINITERED, a modular malware designed to compromise legitimate REDCap files.

Impact and Defensive Measures

INFINITERED’s presence was confirmed in multiple organizations within the US and Canada. The malware includes components for credential harvesting, persistent backdoor access, and data theft. This breach allowed UNC6508 to escalate privileges and exfiltrate sensitive emails using Google’s Workspace features.

In response, GTIG and Mandiant Consulting recommend several defensive actions. These include updating REDCap installations, implementing two-step verification for admin accounts, scanning for INFINITERED using YARA rules, and auditing email compliance rules for unauthorized configurations.

Conclusion and Future Outlook

This incident highlights the ongoing threat posed by state-sponsored cyber groups. The sophisticated methods employed by UNC6508 emphasize the need for enhanced cybersecurity measures in research institutions. Continued vigilance and proactive defense strategies are essential to safeguard critical data from similar threats in the future.

Cyber Security News Tags:Chinese hackers, cyber attack, cyber defense, Cybersecurity, data breach, Espionage, espionage campaign, Google Threat Intelligence, GTIG, InfiniteRed, medical research, North America, REDCap servers, security measures, UNC6508

Post navigation

Previous Post: Cybersecurity Leaders Request Easing of AI Model Restrictions
Next Post: 94% of Cyber Incidents Involve Anonymized Networks

Related Posts

SideWinder Hacking Group Uses ClickOnce-Based Infection Chain to Deploy StealerBot Malware SideWinder Hacking Group Uses ClickOnce-Based Infection Chain to Deploy StealerBot Malware Cyber Security News
Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature Cyber Security News
PoC Exploit Released for Linux-PAM Vulnerability Allowing Root Privilege Escalation PoC Exploit Released for Linux-PAM Vulnerability Allowing Root Privilege Escalation Cyber Security News
Beware of Fake AI Business Tools That Hides Ransomware Beware of Fake AI Business Tools That Hides Ransomware Cyber Security News
FreeBSD-based OPNsense firewall Released for Security Issues and Improvements FreeBSD-based OPNsense firewall Released for Security Issues and Improvements Cyber Security News
New Frontiers In Identity-Based Access Control New Frontiers In Identity-Based Access Control Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026
  • AI Powers Google to Patch Chrome Flaws Swiftly

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026
  • AI Powers Google to Patch Chrome Flaws Swiftly

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark