The Containment Era is here. →Explore

Executive Summary

Between September 2023 and November 2025, the China-linked espionage group UNC6508 infiltrated North American medical, academic, and military research networks by compromising externally facing REDCap servers. They deployed custom malware named INFINITERED, which trojanized REDCap system files to harvest login credentials and establish persistent access. With domain administrator rights, UNC6508 abused Google Workspace's content compliance rules to silently BCC emails containing specific keywords to attacker-controlled Gmail addresses, effectively exfiltrating sensitive research and defense communications without deploying additional malware or generating unusual network traffic.

This incident underscores the evolving tactics of state-sponsored actors who exploit legitimate administrative features within cloud services to conduct stealthy data exfiltration. Organizations must enhance monitoring of administrative configurations and implement robust security measures to detect and prevent such abuses.

Why This Matters Now

The exploitation of legitimate cloud service features for data exfiltration highlights the urgent need for organizations to scrutinize administrative configurations and enhance security protocols to prevent similar stealthy attacks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

They compromised externally facing REDCap servers, deploying the INFINITERED malware to harvest login credentials and establish persistent access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While initial access may still occur, the attacker's ability to exploit vulnerabilities in externally facing servers would likely be constrained, reducing the risk of further compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges by harvesting credentials and deploying malware would likely be constrained, reducing the risk of further compromise.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the network to access sensitive systems and data would likely be constrained, reducing the risk of further compromise.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control through a backdoor would likely be constrained, reducing the risk of further compromise.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate data by abusing content compliance rules would likely be constrained, reducing the risk of data loss.

Impact (Mitigations)

The prolonged undetected theft of sensitive emails would likely be constrained, reducing the overall impact of the attack.

Impact at a Glance

Affected Business Functions

  • Research Data Management
  • Email Communications
  • IT Security Operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Sensitive research data and defense-related emails were accessed and exfiltrated.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and limit access to critical systems.
  • Deploy East-West Traffic Security to monitor and control internal network communications, detecting unauthorized movements.
  • Utilize Multicloud Visibility & Control to gain comprehensive insights into cloud environments and detect anomalous activities.
  • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration through outbound traffic controls.
  • Regularly update and patch externally facing applications like REDCap to mitigate known vulnerabilities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image