Home Tech Google says Chinese hackers cracked Workspace security to hit ‘a diverse set...

Google says Chinese hackers cracked Workspace security to hit ‘a diverse set of national, state, and private medical entities’ including research and defense organizations

37
0
Google says Chinese hackers cracked Workspace security to hit 'a diverse set of national, state, and private medical entities' including research and defense organizations

  • Google GTIG exposes UNC6508, a PRC‑linked group exploiting REDCap servers with custom INFINITERED malware
  • Attackers stole credentials, exfiltrated sensitive data via manipulated compliance rules, and hid for over a year
  • Gmail accounts tied to campaign disabled; admins urged to enforce phishing‑resistant MFA, device‑bound sessions, and advanced protections

For more than a year, Chinese state-sponsored threat actors have been lurking in servers belonging to North American academic, medical, and military research organizations, deploying bespoke malware and exfiltrating sensitive files, experts have warned.

Google Threat Intelligence Group (GTIG) published a new report detailing the recent works of UNC6508, a People’s Republic of China (PRC)-nexus threat actor, who allegedly managed to exploit externally facing Research Electronic Data Capture (REDCap) servers to deploy a custom piece of malware called INFINITERED.

LEAVE A REPLY

Please enter your comment!
Please enter your name here