REDCap
Coverage of REDCap in the Nexus archive.
- Google exposes China espionage group that’s been lurking in networks undetected since 2023
Google threat hunters identified UNC6508, a Chinese state-sponsored espionage group active since 2023, which infiltrated government and private organizations in the U.S. and Canada to steal data from sectors including academia, medicine, and military. The group used a custom backdoor called INFINITERED and exploited REDCap servers, remaining undetected for over a year before being discovered in late 2025.
- PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data
PRC-linked spies, tracked as UNC6508, infiltrated North American medical and military research networks for over a year, using custom malware to snoop through Gmail and steal sensitive data. They targeted defense-related information, drone technology, and research on the Chikungunya virus, exploiting externally facing REDCap servers to gain access.