Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

China-linked group uses InfiniteRed malware to target medical research institutions

The China-linked threat actor UNC6508 exploited vulnerable REDCap servers to deploy the custom InfiniteRed malware, which steals credentials and provides backdoor access. The malware uses a novel exfiltration technique, abusing a legitimate "content compliance rules" feature to email stolen data to a Gmail address. Administrators are advised to upgrade their REDCap instances, implement multi-factor authentication, and use Device Bound Session Credentials.
Read Full Article →

Threat Intelligence China-linked group uses InfiniteRed malware to target medical research institutions June 15, 2026 Share By SC Staff (Adobe Stock) A China-linked espionage campaign has been discovered targeting exposed REDCap servers, leading to the deployment of the InfiniteRed malware and the theft of sensitive data from a North American medical institution. Google Threat Intelligence Group researchers attribute the attacks to a threat actor known as UNC6508, who managed to remain undetected within the victim's network for over a year. The REDCap platform is widely used for managing medical and scientific research databases and surveys, as reported by Bleeping Computer. The attackers, identified as UNC6508, likely exploited older, vulnerable versions of REDCap to gain initial access, although the exact method remains undetermined. Once inside, they deployed a custom malware called InfiniteRed, specifically designed for REDCap systems. This malware, consisting of a persistence module, a credential harvester, and a backdoor, was hidden by trojanizing server system files. The credential harvester captured login details from REDCap pages, while the backdoor allowed UNC6508 to execute commands, upload/download files, run SQL queries, and retrieve stolen credentials. A novel technique observed was the use of a legitimate "content compliance rules" feature in enterprise tools to exfiltrate data via email, by BCCing matched content to a specific Gmail address. The keywords targeted were related to medical research, advanced technology, and military topics. Google has notified multiple compromised organizations in the U.S. and Canada. REDCap administrators are advised to upgrade their instances, implement multi-factor authentication, and use Device Bound Session Credentials. Source: Bleeping Computer SC Staff Related Threat Intelligence FBI shuts down 13 ‘consulting’ websites used for suspected Chinese espionage Laura French June 11, 2026 The sites were used to lure security clearance holders into divulging classified information. Threat Intelligence OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor SC Staff June 11, 2026 Vietnam-aligned threat actor OceanLotus has been linked to two distinct campaigns targeting domestic entities and stock investors with a backdoor known as SPECTRALVIPER, according to ESET. Threat Intelligence Russian national charged in connection with Void Blizzard cyberespionage campaign SC Staff June 11, 2026 Federal prosecutors have charged a Russian national, Denis Nikolayevich Obrezko, with conspiracy to commit unauthorized computer access in connection with a widespread cyberespionage campaign attributed to the Russia-aligned threat group Void Blizzard, according to a recent report by CyberScoop. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms DNS Spoofing Deauthentication Attack Defacement Denial of Service Dictionary Attack Distributed Scans Domain Hijacking DumpSec Dumpster Diving Google Hacking You can skip this ad in 5 seconds

Share this article