Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Cyber Group Exploits Google Workspace to Steal Emails

Chinese Cyber Group Exploits Google Workspace to Steal Emails

Posted on June 15, 2026 By CWS

A cyber espionage group linked to China infiltrated North American medical, academic, and defense research networks, extracting sensitive information over a prolonged period. This breach involved manipulating Google Workspace settings to divert important emails to accounts under their control.

Infiltration of Research Networks

Hackers accessed these networks through a vulnerability in REDCap servers, which are typically used by hospitals and universities to manage research data. By compromising these servers, the group, identified as UNC6508 by Google’s Threat Intelligence Group (GTIG), acquired login credentials, allowing them to embed themselves within the network.

Google’s report, released recently, connects UNC6508 with previous cyber activities against the defense sector. Although the specific organizations affected were not named, they encompass clinical, academic, and military health entities across the United States and Canada. Google has taken steps to alert these organizations and dismantle the cyber group’s infrastructure.

Methods of Entry and Malware Deployment

REDCap, a data management platform, served as the entry point for UNC6508. The cyber group exploited vulnerabilities in externally accessible REDCap servers. While the exact method of initial access remains unclear, probes into older software versions were observed.

Several months post-compromise, custom malware, dubbed INFINITERED, was introduced. This malware modified REDCap’s system files, ensuring persistence by reapplying itself during software upgrades. It also captured login details and served as a backdoor, receiving commands via cookies.

The group’s activities date back to at least September 2023, continuing until November 2025. Once inside the servers, the attackers conducted reconnaissance, obtained credentials, and escalated privileges to access domain administrator accounts.

Exploitation of Google Workspace Rules

UNC6508 leveraged Google Workspace’s content compliance features to steal emails. This legitimate tool was manipulated to forward messages containing specific keywords to an external Gmail account controlled by the attackers. Google has since disabled this account.

The keywords targeted sensitive areas such as strategic policies, military equipment, advanced technologies, and medical research, highlighting the group’s priorities. The use of domain content compliance rules for such purposes had not been previously observed in China-linked attacks, according to GTIG.

Recommendations for Defense

Organizations should start by securing their REDCap servers, updating software, and eliminating outdated versions to prevent similar breaches. On the email front, it’s crucial to review and audit content compliance and mail-forwarding settings to ensure no unauthorized rerouting of emails. Implementing multi-factor authentication for administrator accounts can also mitigate risks, as admin access was pivotal in this attack.

While the exact method of initial access to REDCap servers remains unknown, scrutinizing mail rule changes is vital. Once attackers gain admin privileges, legitimate cloud features can be repurposed for data exfiltration, highlighting the need for comprehensive security audits.

The Hacker News Tags:admin access, Chinese hackers, Cybersecurity, email theft, Google Threat Intelligence, Google Workspace, Malware, Phishing, REDCap servers, UNC6508

Post navigation

Previous Post: Microsoft 365 Copilot Flaw Allows Data Theft in One Click
Next Post: NarwhalRAT Malware Targets Korean Users via LNK Files

Related Posts

Rokarolla Malware Targets Banking Apps with Advanced Tactics Rokarolla Malware Targets Banking Apps with Advanced Tactics The Hacker News
CTEM’s Core: Prioritization and Validation CTEM’s Core: Prioritization and Validation The Hacker News
New TETRA Radio Encryption Flaws Expose Law Enforcement Communications New TETRA Radio Encryption Flaws Expose Law Enforcement Communications The Hacker News
Trump Memo Allows U.S. Firms to Tackle Foreign Cybercrime Trump Memo Allows U.S. Firms to Tackle Foreign Cybercrime The Hacker News
Chinese Cyber Threat Targets Southeast Asian Militaries Chinese Cyber Threat Targets Southeast Asian Militaries The Hacker News
Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows
  • Urgent Alert on Check Point VPN Vulnerabilities
  • Critical Cybersecurity Updates: Microsoft, FortiOS, and More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows
  • Urgent Alert on Check Point VPN Vulnerabilities
  • Critical Cybersecurity Updates: Microsoft, FortiOS, and More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark