UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North American Medical, Academic & Military Research

UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research (TL-2026-0891), also tracked as INFINITERED campaign, is a high-severity advanced persistent threat campaign, first published 2026-06-20 and last reviewed 2026-08-28. It is attributed to UNC6508 (China) with high confidence, affects Vanderbilt University REDCap (Research Electronic Data Capture), maps to 35 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0891

Threat ID
TL-2026-0891
Also known as
INFINITERED campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-06-20
Last reviewed
2026-08-28
Attribution
UNC6508
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
healthcare, medical research, academic research, military, defense, government, biodefense
Target regions
North America, United States, Canada
Detection rules
9
Indicators of compromise
20
Updates
2026-08-28 · revalidated 1× · latest source

Malware and tooling in UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research

Malware and tooling: INFINITERED

Google Threat Intelligence Group (GTIG) and Mandiant attribute, with high confidence, a multi-year espionage campaign to PRC-nexus actor UNC6508 that compromised externally facing, legacy REDCap research servers across North American medical, academic, and military institutions and deployed the custom modular PHP malware INFINITERED (upgrade-interceptor dropper, web-portal credential harvester, and HTTP-cookie C2 backdoor). The actor escalated via reused REDCap credentials into Google Workspace admin and abused content-compliance rules to silently BCC-forward sensitive email to an attacker Gmail account. Activity ran from September 2023 through November 2025, undetected for 18+ months.

How UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research works

Google Threat Intelligence Group (GTIG), in collaboration with Mandiant Consulting, published on 2026-06-15 the details of a long-running PRC-nexus cyber-espionage campaign tracked as UNC6508. The actor targeted REDCap (Research Electronic Data Capture), a web-based platform widely used across North American medical and scientific research communities, by probing externally facing servers for legacy, unpatched versions running side-by-side with current installations — a downgrade-attack opportunity (MITRE T1689). After gaining access to an externally facing REDCap web server, UNC6508 deployed a web shell named help.php, performed internal reconnaissance, and harvested database and service-account credentials. Roughly three months after initial access the actor deployed INFINITERED, a custom, modular PHP malware family that trojanizes legitimate REDCap system files.

INFINITERED has three components. (1) A dropper / upgrade interceptor: it injects malicious code into REDCap upgrade packages (Upgrade.php) so the backdoor and credential harvester are re-injected after legitimate software updates, achieving update-surviving persistence. The injection is delimited by a hardcoded GUID marker (b49e334d-9c01-463e-9bc5-00a6920fb66e, base64 YjQ5ZTMzNGQtOWMwMS00NjNlLTliYzUtMDBhNjkyMGZiNjZl) and includes special handling for AWS Elastic Beanstalk cloud deployments (it pivots on the legitimate '// If running on AWS Elastic Beanstalk' marker). (2) A credential harvester injected into the authentication file: it captures plaintext usernames and passwords from POST login requests, encrypts them with a UTC timestamp using the delimiter '[::]', and covertly stores them inside the legitimate redcap_sessions database table using session IDs prefixed xc32038474a with a 60-day expiration window. (3) A backdoor injected into the custom hooks configuration file so it executes on every REDCap page load; it listens for an HTTP Cookie named REDCAP-TOKEN whose value carries a magic-flag prefix plus an encrypted payload. An empty payload returns a beacon (OS, PHP version, working directory via getcwd(), database credentials, and server software). Command tags support arbitrary system command execution (shell_exec), file upload (move_uploaded_file), retrieval and deletion of harvested credentials, arbitrary SQL execution, and arbitrary file download (command tag ej671a16i7fd8202nu6ltfg5p6x7u).

Approximately 13 months after initial compromise, UNC6508 replayed harvested, overlapping REDCap credentials to compromise a Google Workspace administrator account. The actor then created a content-compliance rule named 'Patroit' (a misspelling of 'Patriot') that silently BCC-forwarded email matching ~150 regular-expression keywords — spanning military strategy, AI/ML, uncrewed-vehicle systems, offensive cyber programs, and medical topics (including the pathogen 'Chikungunya', tied to a July 2025 Guangdong province outbreak indicating real-time, mission-specific tasking) — to the attacker-controlled account BebitaBarefoot774@gmail.com. GTIG notes this abuse of legitimate cloud content-compliance rules for covert exfiltration had never previously been observed from a PRC-nexus actor. To frustrate detection and attribution, UNC6508 routed both the malicious admin login and Gmail access through US-based obfuscation (OBF) infrastructure: compromised ASUS routers (e.g., 23.169.65.49), residential proxies, and VPS hosts. Collection priorities — national defense, Indo-Pacific military operations, AI systems, uncrewed-vehicle technology, offensive cyber programs, and medical/biodefense research — align with PRC state intelligence requirements. GTIG published a YARA rule (G_Backdoor_INFINITERED_1), a VirusTotal collection, and updated Google SecOps with all indicators; no CVE is assigned in the source.

MITRE ATT&CK techniques used in TL-2026-0891

Collection

T1005 Data from Local System; T1114 Email Collection; T1114.003 Email Collection; T1213 Data from Information Repositories

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1090.003 Proxy; T1562.001 Impair Defenses; T1564 Hide Artifacts; T1689 Downgrade Attack

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery

Credential Access

T1056 Input Capture; T1056.003 Input Capture; T1552 Unsecured Credentials

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Privilege Escalation

T1078.004 Valid Accounts

command-and-control

T1090 Proxy

Persistence

T1098 Account Manipulation; T1505 Server Software Component; T1505.003 Server Software Component; T1554 Compromise Host Software Binary

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1550 Use Alternate Authentication Material

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1584.008 Compromise Infrastructure

Reconnaissance

T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research

  • Vanderbilt University — REDCap (Research Electronic Data Capture)
    Vulnerable versions: legacy/unpatched versions run side-by-side with current installations
    Fixed in: latest REDCap release with all legacy versions removed
  • Google — Google Workspace (content compliance / Gmail routing rules)
    Vulnerable versions: admin-configurable content-compliance rules abused via compromised admin account

Remediation for UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research

Patches

  • Patch REDCap to the latest version and fully remove all legacy/older REDCap installations to eliminate downgrade paths

Immediate actions

  • Scan all REDCap servers with GTIG's published YARA rule G_Backdoor_INFINITERED_1 for INFINITERED components
  • Inspect Upgrade.php, custom hooks configuration, and authentication files for the GUID injection marker b49e334d-9c01-463e-9bc5-00a6920fb66e (and its base64 form)
  • Search web roots for the web shell help.php and remove it
  • Audit Google Workspace content-compliance/forwarding rules for unauthorized BCC rules (e.g., 'Patroit') and remove them; disable BCC-forwarding to external addresses
  • Hunt web/proxy logs for the HTTP Cookie REDCAP-TOKEN and for the command tag ej671a16i7fd8202nu6ltfg5p6x7u
  • Query the redcap_sessions table for session IDs prefixed xc32038474a and purge malicious records
  • Block/monitor the IOC IP 23.169.65.49 and the exfil account BebitaBarefoot774@gmail.com

Workarounds

  • Disable side-by-side operation of multiple REDCap versions
  • Restrict external exposure of REDCap admin interfaces and place behind access controls

Longer-term hardening

  • Enforce phishing-resistant 2-Step Verification on all admin and IdP accounts; enroll sensitive accounts in Advanced Protection Program
  • Use unique credentials across security domains to prevent credential replay between REDCap and Workspace
  • Deploy Device Bound Session Credentials (DBSC) with Context-Aware Access to defeat cookie/session theft
  • Enable Data Loss Prevention (DLP) and route Workspace audit logs into SIEM; alert on content-compliance and forwarding-rule changes
  • Establish file-integrity monitoring on REDCap application files to detect upgrade-time re-injection

Weaknesses (CWE) in UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research

CWE-1395, CWE-494, CWE-522, CWE-256, CWE-285

Timeline of UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research

  • Earliest known compromise: UNC6508 exploits an externally facing, legacy/unpatched REDCap research server and deploys the help.php web shell.
  • Internal reconnaissance and discovery; harvesting of database and service-account credentials from the compromised REDCap environment.
  • Approximately three months after initial access, UNC6508 deploys the modular INFINITERED malware (upgrade-interceptor dropper, credential harvester, and HTTP-cookie backdoor) by trojanizing legitimate REDCap files.
  • Roughly 13 months after compromise, harvested overlapping REDCap credentials are replayed to compromise a Google Workspace administrator account via US-based obfuscation infrastructure.
  • Actor creates the 'Patroit' Google Workspace content-compliance rule that silently BCC-forwards email matching ~150 keywords to BebitaBarefoot774@gmail.com.
  • Keyword set includes 'Chikungunya', aligning with a July 2025 Guangdong province outbreak and indicating real-time, mission-specific intelligence tasking.
  • Latest observed UNC6508 activity; campaign had persisted undetected for 18+ months across US and Canadian institutions.
  • Google Threat Intelligence Group and Mandiant publicly disclose the campaign, releasing IOCs, a YARA rule (G_Backdoor_INFINITERED_1), and a VirusTotal collection, and notifying affected organizations.

Update history for TL-2026-0891

Sources cited for UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research

Threats related to UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research

Detection coverage for TL-2026-0891

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0891 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats