UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North American Medical, Academic & Military Research
UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research (TL-2026-0891), also tracked as INFINITERED campaign, is a high-severity advanced persistent threat campaign, first published 2026-06-20 and last reviewed 2026-08-28. It is attributed to UNC6508 (China) with high confidence, affects Vanderbilt University REDCap (Research Electronic Data Capture), maps to 35 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-0891
- Threat ID
- TL-2026-0891
- Also known as
- INFINITERED campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-06-20
- Last reviewed
- 2026-08-28
- Attribution
- UNC6508
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- healthcare, medical research, academic research, military, defense, government, biodefense
- Target regions
- North America, United States, Canada
- Detection rules
- 9
- Indicators of compromise
- 20
- Updates
- 2026-08-28 · revalidated 1× · latest source
Malware and tooling in UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research
Malware and tooling: INFINITERED
Google Threat Intelligence Group (GTIG) and Mandiant attribute, with high confidence, a multi-year espionage campaign to PRC-nexus actor UNC6508 that compromised externally facing, legacy REDCap research servers across North American medical, academic, and military institutions and deployed the custom modular PHP malware INFINITERED (upgrade-interceptor dropper, web-portal credential harvester, and HTTP-cookie C2 backdoor). The actor escalated via reused REDCap credentials into Google Workspace admin and abused content-compliance rules to silently BCC-forward sensitive email to an attacker Gmail account. Activity ran from September 2023 through November 2025, undetected for 18+ months.
How UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research works
Google Threat Intelligence Group (GTIG), in collaboration with Mandiant Consulting, published on 2026-06-15 the details of a long-running PRC-nexus cyber-espionage campaign tracked as UNC6508. The actor targeted REDCap (Research Electronic Data Capture), a web-based platform widely used across North American medical and scientific research communities, by probing externally facing servers for legacy, unpatched versions running side-by-side with current installations — a downgrade-attack opportunity (MITRE T1689). After gaining access to an externally facing REDCap web server, UNC6508 deployed a web shell named help.php, performed internal reconnaissance, and harvested database and service-account credentials. Roughly three months after initial access the actor deployed INFINITERED, a custom, modular PHP malware family that trojanizes legitimate REDCap system files.
INFINITERED has three components. (1) A dropper / upgrade interceptor: it injects malicious code into REDCap upgrade packages (Upgrade.php) so the backdoor and credential harvester are re-injected after legitimate software updates, achieving update-surviving persistence. The injection is delimited by a hardcoded GUID marker (b49e334d-9c01-463e-9bc5-00a6920fb66e, base64 YjQ5ZTMzNGQtOWMwMS00NjNlLTliYzUtMDBhNjkyMGZiNjZl) and includes special handling for AWS Elastic Beanstalk cloud deployments (it pivots on the legitimate '// If running on AWS Elastic Beanstalk' marker). (2) A credential harvester injected into the authentication file: it captures plaintext usernames and passwords from POST login requests, encrypts them with a UTC timestamp using the delimiter '[::]', and covertly stores them inside the legitimate redcap_sessions database table using session IDs prefixed xc32038474a with a 60-day expiration window. (3) A backdoor injected into the custom hooks configuration file so it executes on every REDCap page load; it listens for an HTTP Cookie named REDCAP-TOKEN whose value carries a magic-flag prefix plus an encrypted payload. An empty payload returns a beacon (OS, PHP version, working directory via getcwd(), database credentials, and server software). Command tags support arbitrary system command execution (shell_exec), file upload (move_uploaded_file), retrieval and deletion of harvested credentials, arbitrary SQL execution, and arbitrary file download (command tag ej671a16i7fd8202nu6ltfg5p6x7u).
Approximately 13 months after initial compromise, UNC6508 replayed harvested, overlapping REDCap credentials to compromise a Google Workspace administrator account. The actor then created a content-compliance rule named 'Patroit' (a misspelling of 'Patriot') that silently BCC-forwarded email matching ~150 regular-expression keywords — spanning military strategy, AI/ML, uncrewed-vehicle systems, offensive cyber programs, and medical topics (including the pathogen 'Chikungunya', tied to a July 2025 Guangdong province outbreak indicating real-time, mission-specific tasking) — to the attacker-controlled account BebitaBarefoot774@gmail.com. GTIG notes this abuse of legitimate cloud content-compliance rules for covert exfiltration had never previously been observed from a PRC-nexus actor. To frustrate detection and attribution, UNC6508 routed both the malicious admin login and Gmail access through US-based obfuscation (OBF) infrastructure: compromised ASUS routers (e.g., 23.169.65.49), residential proxies, and VPS hosts. Collection priorities — national defense, Indo-Pacific military operations, AI systems, uncrewed-vehicle technology, offensive cyber programs, and medical/biodefense research — align with PRC state intelligence requirements. GTIG published a YARA rule (G_Backdoor_INFINITERED_1), a VirusTotal collection, and updated Google SecOps with all indicators; no CVE is assigned in the source.
MITRE ATT&CK techniques used in TL-2026-0891
Collection
T1005 Data from Local System; T1114 Email Collection; T1114.003 Email Collection; T1213 Data from Information Repositories
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1090.003 Proxy; T1562.001 Impair Defenses; T1564 Hide Artifacts; T1689 Downgrade Attack
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery
Credential Access
T1056 Input Capture; T1056.003 Input Capture; T1552 Unsecured Credentials
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Privilege Escalation
command-and-control
Persistence
T1098 Account Manipulation; T1505 Server Software Component; T1505.003 Server Software Component; T1554 Compromise Host Software Binary
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1550 Use Alternate Authentication Material
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1584.008 Compromise Infrastructure
Reconnaissance
defense-impairment
Affected products and versions in UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research
- Vanderbilt University — REDCap (Research Electronic Data Capture)
Vulnerable versions: legacy/unpatched versions run side-by-side with current installations
Fixed in: latest REDCap release with all legacy versions removed - Google — Google Workspace (content compliance / Gmail routing rules)
Vulnerable versions: admin-configurable content-compliance rules abused via compromised admin account
Remediation for UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research
Patches
- Patch REDCap to the latest version and fully remove all legacy/older REDCap installations to eliminate downgrade paths
Immediate actions
- Scan all REDCap servers with GTIG's published YARA rule G_Backdoor_INFINITERED_1 for INFINITERED components
- Inspect Upgrade.php, custom hooks configuration, and authentication files for the GUID injection marker b49e334d-9c01-463e-9bc5-00a6920fb66e (and its base64 form)
- Search web roots for the web shell help.php and remove it
- Audit Google Workspace content-compliance/forwarding rules for unauthorized BCC rules (e.g., 'Patroit') and remove them; disable BCC-forwarding to external addresses
- Hunt web/proxy logs for the HTTP Cookie REDCAP-TOKEN and for the command tag ej671a16i7fd8202nu6ltfg5p6x7u
- Query the redcap_sessions table for session IDs prefixed xc32038474a and purge malicious records
- Block/monitor the IOC IP 23.169.65.49 and the exfil account BebitaBarefoot774@gmail.com
Workarounds
- Disable side-by-side operation of multiple REDCap versions
- Restrict external exposure of REDCap admin interfaces and place behind access controls
Longer-term hardening
- Enforce phishing-resistant 2-Step Verification on all admin and IdP accounts; enroll sensitive accounts in Advanced Protection Program
- Use unique credentials across security domains to prevent credential replay between REDCap and Workspace
- Deploy Device Bound Session Credentials (DBSC) with Context-Aware Access to defeat cookie/session theft
- Enable Data Loss Prevention (DLP) and route Workspace audit logs into SIEM; alert on content-compliance and forwarding-rule changes
- Establish file-integrity monitoring on REDCap application files to detect upgrade-time re-injection
Weaknesses (CWE) in UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research
CWE-1395, CWE-494, CWE-522, CWE-256, CWE-285
Timeline of UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research
- Earliest known compromise: UNC6508 exploits an externally facing, legacy/unpatched REDCap research server and deploys the help.php web shell.
- Internal reconnaissance and discovery; harvesting of database and service-account credentials from the compromised REDCap environment.
- Approximately three months after initial access, UNC6508 deploys the modular INFINITERED malware (upgrade-interceptor dropper, credential harvester, and HTTP-cookie backdoor) by trojanizing legitimate REDCap files.
- Roughly 13 months after compromise, harvested overlapping REDCap credentials are replayed to compromise a Google Workspace administrator account via US-based obfuscation infrastructure.
- Actor creates the 'Patroit' Google Workspace content-compliance rule that silently BCC-forwards email matching ~150 keywords to BebitaBarefoot774@gmail.com.
- Keyword set includes 'Chikungunya', aligning with a July 2025 Guangdong province outbreak and indicating real-time, mission-specific intelligence tasking.
- Latest observed UNC6508 activity; campaign had persisted undetected for 18+ months across US and Canadian institutions.
- Google Threat Intelligence Group and Mandiant publicly disclose the campaign, releasing IOCs, a YARA rule (G_Backdoor_INFINITERED_1), and a VirusTotal collection, and notifying affected organizations.
Update history for TL-2026-0891
- 2026-08-28 — UNC6508 (PRC-Nexus) Targets US Medical, Defense, and AI Research via REDCap Exploitation and INFINITERED Backdoor: What changed No evidence-backed change to severity_level, exploitability, status, or attribution_confidence — same UNC6508 REDCap/INFINITERED campaign, same core facts. The newer report contributes MITRE ATT&CK precision (6 techniques not p
Sources cited for UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research
- Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing AI, Cyber, Medical, and National Defense Research
- Custom Malware Named INFINITERED - YARA-L Rules to Detect UNC6508
- PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions
- China-Nexus Actor Spies on US Researchers Undetected for a Year
- Google says PRC-linked spies hid in medical research networks for more than a year
- Chinese hackers breached North American research institutions via REDCap servers
- China-linked hackers target US, Canada research using legacy REDCap exploits
- Google says Chinese hackers cracked Workspace security to hit medical and defense organizations
- PRC-Nexus Hackers Abuse REDCap Servers to Monitor US Medical Research Organizations
Threats related to UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research
Detection coverage for TL-2026-0891
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0891 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.