Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Chinese-linked hackers targeted U.S., Canadian research facilities for a year, Google says

The group used custom malware and Google Workspace compliance rules to steal credentials and route nearly 150 matching emails to an attacker-controlled Gmail account.

  • On Monday, Google Threat Intelligence Group reported that Chinese-linked threat actor UNC6508 breached REDCap servers at North American medical and research institutions, stealing sensitive data between September 2023 and November 2025.
  • Attackers exploited vulnerable REDCap servers to deploy custom malware called "INFINITERED", which trojanized system files to harvest login credentials and maintain persistent remote access.
  • After obtaining administrator access, UNC6508 abused Google Workspace "content compliance rules" to silently BCC-forward emails matching nearly 150 keywords—including military strategy and medical research—to an attacker-controlled Gmail address.
  • GTIG disabled the attacker-controlled Gmail account and notified affected organizations across the United States and Canada, though researchers warned the full extent of the campaign remains unknown.
  • The operation reflects a broader pattern of state-sponsored actors embedding backdoors in critical infrastructure to intercept research and pre-position for potential sabotage, posing persistent security risks to defense, technology, and medical sectors.
Insights by Ground AI

24 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe
Father's Day SaleGet 40% off Vantage subscriptions for yourself or a friend.Get Started

Bias Distribution

  • 60% of the sources are Center
60% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in New York, United States on Monday, June 15, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal