Google Threat Intelligence Group linked China-associated actor UNC6508 to a campaign that breached REDCap servers at a North American medical research organization in September 2023. The group deployed custom InfiniteRed malware three months later and maintained access until November 2025, exfiltrating targeted data through a novel email-based method using content compliance rules.

This rule searched for keywords tied to medical research, advanced technology, military subjects, and geo-strategic policy, automatically forwarding matches as blind carbon copies to the now-disabled address ‘BebitaBarefoot774@gmail.com.’
The campaign maintained strong operational security by routing activity through US-based residential proxies, compromised routers, VPS servers, credential replay, and purpose-built exfiltration infrastructure.
Medical and research institutions running REDCap must prioritize immediate version upgrades and MFA enforcement, as legacy deployments remain prime targets for prolonged espionage campaigns.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Anthropic has launched the Anthropic Cyber Mission to support defenders of critical infrastructure and open-source software with models, engineers, and tools. The initiative starts with the Critical Infrastructure Defense Program and free OSS Scanner amid ongoing challenges in verifying and fixing vulnerabilities.
Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.
The FBI is investigating the dark web sale of scans from more than 153 million US and Canadian drivers licenses obtained via an ongoing breach at a Louisiana identity verification company. The incident underscores the lasting danger of stolen physical identity documents that cannot be reset like passwords and the growing scale of cyber-enabled identity theft.
ShinyHunters published data from 12.9 million genuine Carhartt accounts after the apparel company refused a $3.3 million ransom. The breach, which also exposed records for more than 15,000 employees, originated from Carhartt's Databricks analytics platform.
Sakura Internet disclosed that hackers accessed its sales management system on August 9, potentially compromising data from up to 1.36 million accounts. The breach, discovered during a separate Rental Server investigation, exposes personal and contract details but no confirmed exfiltration or credit card data.