China-Linked Hackers Breach REDCap Servers to Steal Medical Research Data
China-linked hackers breached exposed REDCap servers at North American medical research organizations, deploying custom InfiniteRed malware to steal credentials, access sensitive research data, and exfiltrate information through both backdoors and abused enterprise email rules.
Google security researchers have uncovered a China-linked cyber espionage campaign targeting exposed REDCap servers at medical and scientific research organizations in North America.
The campaign was attributed by the Google Threat Intelligence Group to a threat actor tracked as UNC6508. According to Google, the attackers maintained access to at least one medical research organization for more than a year while deploying custom malware designed specifically to compromise REDCap environments and steal sensitive research data.
REDCap, short for Research Electronic Data Capture, is widely used by universities, hospitals, public health agencies, and research institutions to build and manage databases, surveys, clinical studies, and regulated scientific research workflows. Because these systems often store sensitive medical, academic, policy, and clinical trial data, they are high-value targets for state-linked espionage groups.
Google said it could not confirm the exact initial access method, but researchers observed UNC6508 probing older and vulnerable REDCap deployments. The compromise of the medical research organization reportedly began in September 2023, with malicious activity continuing until November 2025.
Roughly three months after gaining access, the attackers deployed a custom malware framework called InfiniteRed, which was built to operate inside REDCap systems. The malware hid its components by modifying or trojanizing legitimate server files, allowing the attackers to blend into the application environment and remain undetected.
InfiniteRed includes three main components: a persistence and update module, a credential harvesting module, and a backdoor.
The credential harvester captures usernames and passwords submitted through REDCap login pages. Instead of immediately sending the stolen credentials out of the network, the malware encrypts them and stores them inside local REDCap database tables for later retrieval. This approach helps the attackers reduce obvious outbound traffic and keep stolen credentials close to the compromised application.
The backdoor receives commands through HTTP cookies, giving UNC6508 a stealthy command channel inside normal web traffic. Through this backdoor, the attackers could execute shell commands, upload and download files, run SQL queries, retrieve stolen credentials, delete credential records, and collect system and database information.
One of the more notable techniques observed in the campaign involved the abuse of a legitimate enterprise productivity feature: content compliance rules. After gaining administrator access, UNC6508 created a rule named “Patroit” that searched the organization’s email environment for specific keywords, content patterns, email addresses, and phone numbers.
When matching content was found, the rule automatically forwarded copies using blind carbon copy to an external Gmail account, which has since been disabled by Google.
This technique is significant because it allowed the attackers to use built-in administrative features for data exfiltration rather than relying only on custom malware. By abusing trusted platform functionality, threat actors can make malicious activity look more like normal administrative behavior.
Google said the search terms used in the campaign focused on topics tied to medical research, advanced technology, military readiness, and geo-strategic policy. That targeting suggests the attackers were not only interested in patient or account data, but also in research intelligence and policy-relevant information.
GTIG also observed strong operational security throughout the campaign. The attackers used U.S.-based residential proxy infrastructure, compromised routers, virtual private servers, credential replay, and dedicated exfiltration infrastructure to hide their activity and make attribution more difficult.
Google notified multiple organizations in the United States and Canada that were compromised with InfiniteRed. According to the company, the affected research areas span a wide range of modern medicine, including molecular discovery, clinical drug trials, state-level public health policy, and military readiness.
The campaign highlights the growing cyber risk facing healthcare and research institutions. Medical research networks often contain a combination of regulated data, intellectual property, grant-funded research, clinical trial information, and sensitive policy materials. For nation-state actors, that data can be valuable for economic, scientific, military, and strategic purposes.
REDCap administrators are being urged to upgrade to the latest available version and retire legacy deployments. Organizations should also review server exposure, restrict internet-facing access where possible, and closely monitor application files for unauthorized modifications.
Google also recommends enabling multi-factor authentication or two-step verification for high-privilege accounts and using protections such as Device Bound Session Credentials to reduce the risk of session hijacking.
Security teams should review Google’s published indicators of compromise and YARA rules to scan for InfiniteRed infections. They should also investigate unusual REDCap database entries, unexpected changes to application files, suspicious HTTP cookie-based command activity, abnormal administrator actions, and any content compliance rules that forward data to external accounts.
For medical and academic institutions, the incident reinforces a broader security lesson: research platforms should be treated as critical infrastructure. Systems that store clinical, academic, public health, and defense-adjacent research data require strong patch management, strict administrative controls, detailed logging, and continuous monitoring.
UNC6508’s use of custom REDCap malware shows that attackers are increasingly building tools tailored to the specific applications used by high-value sectors. Defending against these campaigns requires more than perimeter security. Organizations need visibility into application behavior, administrative changes, identity activity, and unusual data movement across cloud and on-premises environments.
Comments
0 public comments
No comments yet
Be the first to add a comment to this article.
Add a comment
Please sign in to comment on this article.
Sign In