Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A China-linked threat group designated UNC6508 compromised at least one North American medical research organization by exploiting internet-exposed REDCap servers, maintaining undetected access for more than two years, from September 2023 through November 2025. The group deployed a purpose-built backdoor called InfiniteRed, harvested credentials, and exfiltrated sensitive research data by abusing Google Workspace content compliance rules, a novel technique not previously seen from China-nexus actors. Medical and scientific research institutions running internet-facing REDCap installations face immediate risk of data theft, prolonged silent access, and potential loss of proprietary research assets.

Author

Tech Jacks Solutions