Google says China-linked UNC6508 hid in REDCap servers at North American medical and military research organizations for more than a year

Google says a China-linked espionage group spent more than a year inside North American medical and military research networks, stealing sensitive data and searching Gmail for defense and disease-research information. Google tracks the group as UNC6508 and says the intrusions began by exploiting internet-facing REDCap (Research Electronic Data Capture) servers, then deploying custom InfiniteRed malware to maintain access, harvest REDCap credentials, backdoor the application, and search for data tied to drone technology, defense companies, and Chikungunya research.
Why it matters: Organizations running REDCap in healthcare, research, government, or defense-adjacent environments should treat this as a high-priority intrusion risk and investigate for compromise, not just patch. The campaign shows long-term espionage against sensitive medical and military research, including theft from email and internal systems.

Sources

Majority of Internet-Accessible REDCap Servers Outdated
Ionut Arghire 2026.06.18 94% relevant
This article updates the same underlying UNC6508 REDCap espionage campaign with new internet-wide telemetry from Censys, estimating roughly 8,500 exposed REDCap instances globally and finding only about 1% on the latest version, which strengthens the exposure and urgency around the previously reported targeting of legacy REDCap servers.
Chinese Hackers Target Medical, Military, and AI Research in North America
Eduard Kovacs 2026.06.15 97% relevant
This article is a direct report on the same GTIG disclosure, adding plain-language detail that UNC6508 targeted REDCap servers at medical, academic, military, and AI-related organizations in North America, deployed the InfiniteRed malware, abused content compliance rules for email exfiltration, and used legacy vulnerable REDCap instances and obfuscation infrastructure.
PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data
2026.06.15 100% relevant
This article appears to be the first detailed report establishing this specific UNC6508 espionage campaign against REDCap-backed medical and military research environments.
Chinese hackers breach REDCap servers, steal medical research
Bill Toulas 2026.06.15 98% relevant
This is the same underlying GTIG disclosure about UNC6508 compromising vulnerable REDCap servers, deploying InfiniteRed malware, stealing credentials, and exfiltrating medical and research data from North American organizations over a year-long intrusion. It adds reporting emphasis on the medical-research victim and the email-rule exfiltration method.
← Back to all stories