Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
Google Threat Intelligence Group attributed a long-running campaign to UNC6508, which targeted North American academic, medical, and military research institutions by compromising REDCap servers, deploying the INFINITERED malware, and stealing credentials and data. The actor later abused enterprise content compliance rules to silently forward sensitive emails to a threat actor-controlled Gmail account while using strong operational security and proxy infrastructure to stay hidden. #UNC6508 #REDCap #INFINITERED #BebitaBarefoot774gmailcom

Keypoints

  • GTIG linked the campaign with high confidence to UNC6508, a PRC-nexus threat actor.
  • The victim set included North American academic, medical, and military research organizations, with activity spanning more than a year.
  • Initial access was achieved by exploiting externally facing REDCap servers and then deploying the INFINITERED malware.
  • INFINITERED harvested login credentials, persisted through upgrades, and maintained backdoor access on compromised systems.
  • UNC6508 used stolen credentials to pivot into internal networks and later access administrator accounts.
  • The actor abused content compliance rules to BCC-forward matching emails to a Gmail account under their control for covert exfiltration.
  • GTIG disrupted associated infrastructure, notified victims, and published detections, IOCs, and hardening guidance.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – UNC6508 gained access by exploiting exposed REDCap servers (‘exploited externally facing REDCap servers’).
  • [T1505.003] Server Software Component: Web Shell – The actor deployed a web shell named help.php to maintain persistence and upload files (‘deployed a web shell named “help.php”‘).
  • [T1554] Compromise Client Software Binary – INFINITERED modified legitimate REDCap files and intercepted the upgrade process to persist across versions (‘injects its code into new REDCap versions by intercepting the upgrade process’).
  • [T1027] Obfuscated Files or Information – The malware used Base64 and GUID-delimited payloads to hide malicious logic (‘Base64 GUID delimiter’, ‘extract the malicious logic using GUID delimiter’).
  • [T1090.003] Proxy: Multi-hop Proxy – UNC6508 routed activity through OBF networks, compromised routers, residential proxies, and VPS infrastructure (‘routing traffic from offensive operations through a mix of compromised routers, residential proxies, Virtual Private Servers’).
  • [T1562.001] Impair Defenses: Disable or Modify Tools – The actor abused content compliance rules to silently forward emails and avoid normal user-visible handling (‘Silently “BCC-forward” matched emails’).
  • [T1689] Downgrade Attack – UNC6508 probed for and abused vulnerable legacy REDCap versions side-by-side with newer ones (‘probing for these vulnerable legacy versions’).
  • [T1555] Credentials from Password Stores – INFINITERED collected credentials from local REDCap storage and configuration data (‘hides inside a local REDCap sessions database table’).
  • [T1056.003] Input Capture: Web Portal Capture – The credential harvester captured usernames and passwords submitted through the login page (‘captures usernames and passwords submitted via POST requests during the login process’).
  • [T1114.003] Email Collection: Email Forwarding Rule – UNC6508 created a compliance rule named “Patroit” to forward matching messages to attacker-controlled email (‘used regular expressions to match … emails’).
  • [T1213] Data from Information Repositories – The actor searched emails and other data for strategic intelligence keywords (‘matching on keyword and email address patterns in sent or received emails’).
  • [T1071.001] Application Layer Protocol: Web Protocols – INFINITERED used HTTP cookie parameters for command-and-control traffic (‘REDCAP-TOKEN’ cookie parameter).
  • [T1567] Exfiltration Over Web Service – Exfiltrated emails were forwarded to a Gmail account controlled by the threat actor (‘BCC-forwarded to a threat actor-controlled Gmail address’).
  • [T1071.001] Application Layer Protocol: Web Protocols – The malware returned system information and received commands through HTTP-based cookie communication (‘beacons system information’ and ‘parse the payload for command tags’).

Indicators of Compromise

  • [Email] Exfiltration account used for covert forwarding – [email protected]
  • [IP address] Source of admin login from compromised infrastructure – 23.169.65.49
  • [File hashes] INFINITERED-related malware and persistence components – ba6b73b0ca0dc7f86b3b397893ac32d729fd53f9df20643288f141f29d020af7, db65c1b9f9e4cb4d729f45ad4b6fcf3e277caf9eb4c875425dec93fd883f9136, and 5 more hashes
  • [File names] Web shell and REDCap-related malicious files – help.php, redcap_connect.php
  • [GUID / string marker] INFINITERED version delimiter and database prefix – b49e334d-9c01-463e-9bc5-00a6920fb66e, xc32038474a
  • [Cookie / command tag] C2 and command marker values used by INFINITERED – REDCAP-TOKEN, ej671a16i7fd8202nu6ltfg5p6x7u


Read more: https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research/