Silent exfiltration from REDCap: how INFINITERED and UNS6508 used Google Workspace to steal critical research

Author: Published 5 min de lectura 154 reading

The images in this article were generated with artificial intelligence. How we publish

A group linked to China, identified by Google as UNC6508, took advantage of a back door installed on exposed REDCap servers to stay within North American medical, academic and military research networks for more than a year, stealing mail and sensitive data without generating the kind of noise that traditional campaigns often produce. The most worrying finding was not so much the backdoor - GTIG called the malicious module INFINITERED - but the way the attackers released the information: they modified legitimate rules of content compliance in Google Workspace to copy by BCC to a Gmail account controlled by them any mail that coincided with almost 150 keywords.

The technique is effective because it explores two realities of current cybersecurity: first, many scientific and clinical institutions publish and expose tools such as REDCap to facilitate collaborative research, and second, cloud platforms incorporate automation and compliance functions that, if they fall into wrong hands, allow exfiltering data without installing additional malware or generating abnormal traffic. REDCap allows legit versions running along with the current version, which facilitates retreating attacks on vulnerable versions; INFINITERED took advantage of this situation to integrate into the update flow itself and maintain persistence. Beyond the technical intrusion, the target of the collection - geo-strategic policy, military equipment, advanced research and even epidemiological terms like "chikungunya" - shows that the attackers sought both critical intellectual property and state intelligence.

Silent exfiltration from REDCap: how INFINITERED and UNS6508 used Google Workspace to steal critical research
Image generated with IA.

The implications are double: on the one hand, loss of biomedical research and possible impact on health responses and academic collaborations; on the other, risk of exfiltration of information affecting national security and military preparation. For institutions that handle sensitive data, this must change the prioritization of controls: it is not enough to protect exposed servers, it is necessary to audit and control cloud management functions that can transform a legitimate function into a leak channel. Google notified the victims and deactivated the account used by the attackers, but the episode stresses that the perimeter is no longer just the affected machine but also the managed services associated with that administrative identity.

The specific actions that any technical or security officer should implement immediately include reviewing all REDCap instances accessible from the Internet, removing old versions rather than allowing coexistence, applying patches and rebuilding servers engaged from clean images; REDCap is a reference project and its official website contains useful resources for managers, for example in projectredcap.org. In parallel, it is essential to audit compliance and forwarding rules in Google Workspace or other cloud mail suites: look for rules that do BCC, send or copy messages to external addresses and check the management records to know who and when created or modified those rules - Google's official documentation on content rules can serve as a starting point: Set up rules to examine content and take action.

From the point of view of detection and research, do not rely solely on network telemetry. Review management audit logs, superuser sessions and changes in compliance policies; seek to create rules with deliberate typographic errors (the report cites a miswritten term as "Patroit") and key word patterns related to intelligence collections. Running searches and fighters for indicators associated with INFINITERED and UNC6508, and correlating them with access to service accounts and privilege elevations, is a priority; Google Threat Intelligence Group publishes analysis and metrics that can help guide these hunts, and its outreach page offers useful contexts: Google Threat Analysis Group.

Silent exfiltration from REDCap: how INFINITERED and UNS6508 used Google Workspace to steal critical research
Image generated with IA.

In terms of organizational and governance mitigation, apply phishing-resistant authentication multifactor in all administrative and high-risk accounts, segmental research environments so that a committed credential does not allow direct jump to critical domains, and limit the capacity to create compliance rules to a minimum group with formal approval. Implement real-time detection and alerts on changes in mail policies and the creation of rules that post out of the domain, and consider additional controls such as immutable audit records and double approval procedures for sensitive changes.

If you suspect it has been affected, treat the response as an intrusion by laterality: disconnect and preserve systems for forensic analysis, change and rotate credentials and associated keys, re-establish administrator sessions, revoke or rebuild compromised REDCap servers and seek evidence of lateral movement to domain accounts or mail services. In addition, coordinate with partners and competent authorities if there is evidence of exfiltration of health data or regulated information. The security community must understand that this case shows a trend: cloud functionalities designed for compliance or convenience may be the most silent and effective link for exfiltration when an actor achieves administrative privileges.

In short, protecting research environments is not just patching applications; it is controlling who can manipulate cloud services policies and visualize any automation that can copy or divert messages. Auditing REDCap, applying strict cloud management policies, demanding phishing-resistant MFA and establishing specific detections for changes in mail rules are steps that reduce the risk that a technical intrusion will become a massive leak of scientific knowledge and sensitive data.

Coverage

Related

More news on the same subject.