UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North American Medical, Academic & Military Research — Threadlinqs Intelligence
As of 2026-06-20, UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North American Medical, Academic & Military Research is a high-severity apt threat attributed to UNC6508 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0891 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: UNC6508 · China · ESPIONAGE
Google Threat Intelligence Group (GTIG) and Mandiant attribute, with high confidence, a multi-year espionage campaign to PRC-nexus actor UNC6508 that compromised externally facing, legacy REDCap
Google Threat Intelligence Group (GTIG), in collaboration with Mandiant Consulting, published on 2026-06-15 the details of a long-running PRC-nexus cyber-espionage campaign tracked as UNC6508. The actor targeted REDCap (Research Electronic Data Capture), a web-based platform widely used across North American medical and scientific research communities, by probing externally facing servers for legacy, unpatched versions running side-by-side with current installations — a downgrade-attack opportunity (MITRE T1689). After gaining access to an externally facing REDCap web server, UNC6508 deployed a web shell named help.php, performed internal reconnaissance, and harvested database and service-account credentials. Roughly three months after initial access the actor deployed INFINITERED, a custom, modular PHP malware family that trojanizes legitimate REDCap system files.
INFINITERED has three components. (1) A dropper / upgrade interceptor: it injects malicious code into REDCap upgrade packages (Upgrade.php) so the backdoor and credential harvester are re-injected after legitimate software updates, achieving update-surviving persistence. The injection is delimited by a hardcoded GUID marker (b49e334d-9c01-463e-9bc5-00a6920fb66e, base64 YjQ5ZTMzNGQtOWMwMS00NjNlLTliYzUtMDBhNjkyMGZiNjZl) and includes special handling for AWS Elastic Beanstalk cloud deployments (it pivots on the legitimate '// If running on AWS Elastic Beanstalk' marker). (2) A credential harvester injected into the authentication file: it captures plaintext usernames and passwords from POST login requests, encrypts them with a UTC timestamp using the delimiter '[::]', and covertly stores them inside the legitimate redcap_sessions database table using session IDs prefixed xc32038474a with a 60-day expiration window. (3) A backdoor injected into the custom hooks configuration file so it executes on every REDCap page load; it listens for an HTTP Cookie named REDCAP-TOKEN whose value carries a magic-flag prefix plus an encrypted payload. An empty payload returns a beacon (OS, PHP version, working directory via getcwd(), database credentials, and server software). Command tags support arbitrary system command execution (shell_exec), file upload (move_uploaded_file), retrieval and deletion of harvested credentials, arbitrary SQL execution, and arbitrary file download (command tag ej671a16i7fd8202nu6ltfg5p6x7u).
Approximately 13 months after initial compromise, UNC6508 replayed harvested, overlapping REDCap credentials to compromise a Google Workspace administrator account. The actor then created a content-compliance rule named 'Patroit' (a misspelling of 'Patriot') that silently BCC-forwarded email matching ~150 regular-expression keywords — spanning military strategy, AI/ML, uncrewed-vehicle systems, offensive cyber programs, and medical topics (including the pathogen 'Chikungunya', tied to a July 2025 Guangdong province outbreak indicating real-time, mission-specific tasking) — to the attacker-controlled account BebitaBarefoot774@gmail.com. GTIG notes this abuse of legitimate cloud content-compliance rules for covert exfiltration had never previously been observed from a PRC-nexus actor. To frustrate detection and attribution, UNC6508 routed both the malicious admin login and Gmail access through US-based obfuscation (OBF) infrastructure: compromised ASUS routers (e.g., 23.169.65.49), residential proxies, and VPS hosts. Collection priorities — national defense, Indo-Pacific military operations, AI systems, uncrewed-vehicle technology, offensive cyber programs, and medical/biodefense research — align with PRC state intelligence requirements. GTIG published a YARA rule (G_Backdoor_INFINITERED_1), a VirusTotal collection, and updated Google SecOps with all indicators; no CVE is assigned in the source.
Weaknesses (CWE)
CWE-1395, CWE-494, CWE-522, CWE-256, CWE-285
Target sectors: healthcare, medical research, academic research, military, defense, government, biodefense
Target regions: North America, United States, Canada
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1595, T1583, T1584, T1190, T1505, T1554, T1098, T1562, T1027, T1090