惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
D
Docker
月光博客
月光博客
MongoDB | Blog
MongoDB | Blog
Vercel News
Vercel News
美团技术团队
博客园 - 叶小钗
I
InfoQ
Jina AI
Jina AI
博客园 - 司徒正美
雷峰网
雷峰网
B
Blog
Y
Y Combinator Blog
A
About on SuperTechFans
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Recent Announcements
Recent Announcements
V
V2EX
N
Netflix TechBlog - Medium

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber
China-linked hackers target US, Canada research using leg...
Shweta Sharma · 2026-06-16 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Attackers hijacked REDCap upgrade processes to plant malware and spy on academic, healthcare, and defense research networks.

Google is warning of a cyber espionage campaign linked to a China-nexus threat actor, UNC6508, that kept close tabs on valuable US and Canadian research environments for over a year.

The campaign abused REDCap, a widely adopted platform for collecting and managing research data. Attackers, now disrupted, intercepted REDCap’s upgrade process to inject persistence malware.

According to Google’s Threat Intelligence Group (GTIG), the campaign was particularly interested in academic institutions, medical research centers, healthcare providers, military health networks, and defense-focused research programs.

Google said UNC6508 historically infected the legacy REDCap versions, and the observed campaign was just building on that initial compromise to push code for persistence.

“GTIG was not able to confirm how UNC6508 initially gained access to the REDCap server,” GTIG researchers said in a blog post. “By design, REDCap allows administrators to continue running legacy software side-by-side with the current version. UNC6508 was observed probing for these vulnerable legacy versions on several target organizations’ REDCap systems.”

The state-sponsored group was after a wide range of sensitive research and defense-related information, spanning national security, AI, cyber operations, and medical research.

Research platform became the front door

Other than persistence, the campaign supported credential discovery, internal reconnaissance, and post-compromise operations.

UNC6508 used a payload tracked as INFINITERED, which is a modular malware designed to trojanize legitimate REDCap system files. The malware has three dedicated components: a dropper and upgrade Interception, a credential harvester, and a backdoor with command and control (c2).

The upgrade interception module reads the legacy REDCap versions still accessible on some current REDCap deployments, already infected with malicious logic through an unknown initial access, and extracts the malicious logic from that version. It then injects this code into the upgrade system file.

Parallelly, the other two modules inject credential harvester code into the authentication system file, and backdoor code into the custom hooks configuration file, respectively.

“Upon establishing a foothold on the REDCap server, UNC6508 performed internal reconnaissance and credential discovery to obtain database and service account credentials,” GTIG researchers said in a blog post. “The threat actor also deployed a web shell named “help.php”, which maintained persistence and functioned as an uploader in the REDCap application.”

The backdoor supports a range of remote commands that allow operators to manage files, execute shell commands, gather system information, and maintain control over compromised REDCap servers, providing UNC6508 with a rich post-compromise toolkit.

REDCap’s maintainers did not respond to CSO’s request for comments.

Hunting for and removing INFINITERED

Because INFINITERED embeds itself into REDCap’s upgrade workflow and modifies legitimate application files, organizations are encouraged to inspect REDCap environments for unauthorized file modifications, unexpected web shells, and signs of credential harvesting activity using the GTIG provided YARA rule.

Google also recommends upgrading vulnerable REDCap deployments, reviewing legacy versions that remain accessible alongside current installations, and validating the integrity of application files before and after upgrades. Enforcing phishing-resistant 2-step verification, device-bound session credentials, and relevant DLP rules were also recommended for tighter controls.

Google said it notified several organizations across the US and Canada that it believes were compromised with INFINITERED, and offered remediation assistance.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.