Chinese hackers breach REDCap servers, steal medical research

Chinese hackers breach REDCap servers, steal medical research β€” Cybersecurity | Versia.media

A cyberespionage campaign linked to China targeted vulnerable REDCap servers to install the InfiniteRed malware and pilfer sensitive data from a medical institution in North America.

Researchers from Google Threat Intelligence Group (GTIG) attribute the attacks to a threat actor designated as UNC6508, who operated undetected within the victim network for over a year.

The REDCap platform is extensively utilized in medical and scientific research for creating and managing databases and surveys that adhere to regulations for medical and scientific studies.

Although the researchers could not pinpoint the precise initial compromise vector, they noted UNC6508 probing older, susceptible versions of REDCap.

According to the investigation, the compromise of the medical research organization took place in September 2023, with malicious activities persisting for over a year until November 2025.

GTIG reports that three months after the initial breach, the attackers deployed the custom 'InfiniteRed' malware, tailored specifically for REDCap systems, and concealed its components by trojanizing the server's system files.

InfiniteRed consists of three elements: a persistence/update module, a credential harvester, and a backdoor.

The login harvester captures usernames and passwords submitted through REDCap login pages, then encrypts and stores them in local REDCap database tables for later retrieval.

The backdoor, which receives commands via HTTP cookies, grants UNC6508 the following capabilities:

Execute shell commands

Upload files to the REDCap server

Download files from the server

Run arbitrary SQL queries

Retrieve stolen credentials

Delete stolen credential records

Return system and database information

A notable technique in this campaign, new for China-linked threat actors, involves using the legitimate 'content compliance rules' feature found in cloud-based enterprise productivity tools to exfiltrate data via email.

After obtaining administrator access, UNC6508 established a content compliance rule named "Patroit," which scans the organization for specific keywords, content patterns, email addresses, and phone numbers.

Any matches are then automatically sent as a blind carbon copy (BCC) to 'BebitaBarefoot774@gmail.com,' which has since been disabled by Google.

The keywords used to identify valuable data relate to medical research, advanced technology, military topics, and geo-strategic policy.

GTIG observed a high level of operational security throughout this campaign, including the use of US-based residential proxy infrastructure, compromised routers, VPS, credential replay, and dedicated infrastructure for data exfiltration.

Google notified multiple organizations in the U.S. and Canada that were compromised with the InfiniteRed malware.

"Their research areas span a broad spectrum of modern medicine, from molecular discovery and clinical drug trials to state-level public health policy and military readiness."

REDCap administrators are advised to upgrade their instances to the latest available versions and remove legacy deployments.

Google also recommends using MFA/2SV on high-privilege accounts and Device Bound Session Credentials (DBSC) to prevent session hijacking.

YARA rules and indicators of compromise (IoCs) are included in the report to help scan environments for InfiniteRed malware infections.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Related Articles:

Chinese APT deploys new malware to keep access to hacked networks

Chinese hackers target telcos with new Linux, Windows malware

New GopherWhisper APT group abuses Outlook, Slack, Discord for comms

Chinese hackers hijack auth flow, spy on isolated network for a decade

China-linked JDY botnet expands targeting of U.S. military networks

← Cybersecurity