- Google GTIG exposes UNC6508, a PRC‑linked group exploiting REDCap servers with custom INFINITERED malware
- Attackers stole credentials, exfiltrated sensitive data via manipulated compliance rules, and hid for over a year
- Gmail accounts tied to campaign disabled; admins urged to enforce phishing‑resistant MFA, device‑bound sessions, and advanced protections
For more than a year, Chinese state-sponsored threat actors have been lurking in servers belonging to North American academic, medical, and military research organizations, deploying bespoke malware and exfiltrating sensitive files, experts have warned.