The China-linked threat actor UNC6508 compromised vulnerable REDCap servers to gain persistent access to North American medical research institutions, deploying custom malware for data exfiltration. The article does not provide specific CVE details, affected version ranges, fixed versions, or workarounds for the REDCap vulnerabilities exploited.
A China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. UNC6508 exploits vulnerable REDCap servers GTIG attributed the campaign to UNC6508, a threat actor linked to the People’s Republic of China that remained undetected in victim environments for more than a year. According to the researchers, the activity began in September 2023 … More → The post Chinese hackers breached North American research institutions via REDCap servers appeared first on Help Net Security .