Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes. Reporting from 2019 and a Google Threat Intelligence Group (GTIG) investigation published June 15, 2026, describe China-linked cyber-espionage activity against medical and research organizations. The newer campaign, attributed to the PRC-nexus actor UNC6508, exploited externally exposed REDCap servers and used stolen credentials to reach email systems.

What has been reported about attacks on medical research?

SecurityWeek reported on August 21, 2019, citing FireEye, that multiple China-linked advanced persistent threat groups had targeted healthcare research organizations in the United States and elsewhere. The reported activity included:

Group Reported targets or activity
APT41 A U.S. research university, a medical-device subsidiary, and a biotechnology company.
APT10 Spear-phishing aimed at healthcare entities in Japan.
APT18/Wekby Biotechnology, pharmaceutical, and cancer-research organizations.

FireEye also described theft of large sets of personally identifiable information (PII) and protected health information (PHI), including in several high-profile U.S. breaches in 2015. These 2019 reports describe activity by multiple groups; they should not be treated as evidence that every incident used the same tools or belonged to one campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why target cancer, biotech, and clinical research?

Research organizations hold information with both scientific and personal value. FireEye’s explanation, quoted by SecurityWeek in 2019, was that stolen medical research could help Chinese corporations bring drugs to market faster than Western competitors. That is a proposed strategic benefit, not proof of the motive behind every intrusion.

#1 Best Overall
Sale
Merriam-Webster's Medical Dictionary, Newest Edition, Mass-Market Paperback
  • Essential guide to the language of medicine
  • Includes 1 000 new words and senses
  • Covers the latest brand names and generic equivalents of common drugs
  • Pronunciation provided for all entries

GTIG’s June 2026 account describes a broader intelligence interest in its UNC6508 campaign. Targeted institutions included clinical providers, academic centers, military health institutions, professional advocacy groups, and health regulators. The research areas ranged from molecular discovery and clinical drug trials to public-health policy and military readiness. The same collection rules also searched for information on national security, artificial intelligence, drones, cyber-offensive research, defense technology, naval assets, diplomatic entities, and military command units.

What are UNC6508 and INFINITERED?

UNC6508 is GTIG’s designation for a threat actor it describes as having a People’s Republic of China (PRC) nexus. GTIG identified the campaign as targeting North American academic, medical, and military research institutions. Its earliest known compromise in this campaign occurred in September 2023.

INFINITERED is the malware GTIG says the actor deployed after compromising externally facing REDCap installations. REDCap is used to build and manage clinical research databases and surveys. GTIG describes INFINITERED as a set of modules that can intercept REDCap upgrades, harvest credentials, and provide backdoor access. The server compromise therefore could become a route into accounts and services beyond the REDCap application itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the UNC6508 attack chain worked

  1. Find an exposed route in. The actor probed externally accessible REDCap installations, including for vulnerable legacy versions, and exploited a server.
  2. Establish a foothold and investigate. GTIG says the actor deployed a help.php web shell and conducted internal reconnaissance.
  3. Install INFINITERED. Its reported modules enabled upgrade interception, credential harvesting, and backdoor or command-and-control functions.
  4. Capture REDCap login credentials. The malware captured usernames and passwords through the REDCap login process and concealed them in a legitimate session table.
  5. Use the credentials to expand access. GTIG says the actor replayed captured credentials and eventually reached a domain administrator account.
  6. Forward selected email covertly. The actor created a content-compliance rule that silently BCC-forwarded matching messages to an actor-controlled Gmail account.
  7. Make detection and attribution harder. GTIG reports use of obfuscation networks, bulk-created accounts, compromised routers, residential proxies, and virtual private server (VPS) infrastructure.

The email rule is a distinct collection method from stealing a research database: it can expose matching messages without a user seeing them in the ordinary flow of email. Its presence also shows why defenders should monitor administrative configuration changes, not just malware on research servers.

How can a hospital or university protect a REDCap server?

Reduce exposure at the application layer

  • Fully update REDCap and remove obsolete versions, as GTIG recommends. Include externally facing installations in the organization’s patch and asset-management process.
  • Investigate unexpected files such as help.php, suspicious changes around upgrades, and signs that an application server is being used for internal reconnaissance.
  • Scan for INFINITERED using the YARA rule and indicators of compromise supplied by GTIG. Treat a match as a reason to investigate the affected host and connected accounts, rather than as a complete measure of compromise.

Protect privileged accounts and sessions

  • Require phishing-resistant 2-Step Verification for enterprise administrators. A FIDO2 security key is one implementation option; GTIG recommends the control, not a particular brand.
  • Consider Advanced Protection for sensitive accounts.
  • Use device-bound session credentials to help prevent stolen cookies from being reused, and enable password-leak detection to identify exposed passwords.
  • Review whether credentials used for REDCap or other research systems are reused elsewhere. A password captured at an application login can create risk beyond that application.

Make covert email collection visible

  • Enable and review audit logs, and define data loss prevention (DLP) rules appropriate to the organization’s sensitive research and health information.
  • Audit content-compliance rule changes and alert on unexpected forwarding or BCC destinations, especially changes made by privileged accounts.
  • Include Workspace logs in a security information and event management (SIEM) system so investigators can correlate mail-rule changes with account and endpoint activity.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about the scale—and what is not?

GTIG says affected institutions employ thousands of people and have combined research budgets in the billions, but it does not give a precise combined budget figure. The available reporting does not establish a reliable total count of medical-research victims or total financial losses across these campaigns. The confirmed picture is one of persistent targeting and varied collection methods, not a quantified census of every affected organization.

Sources: SecurityWeek, August 21, 2019, citing FireEye; Google Threat Intelligence Group, June 15, 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.