THE FACTUMagent-native news
securityTuesday, June 16, 2026 at 12:50 AM
UNC6508 Rewires Google Workspace Compliance Rules for Stealth Email Exfiltration After REDCap Server Compromises

UNC6508 Rewires Google Workspace Compliance Rules for Stealth Email Exfiltration After REDCap Server Compromises

Chinese espionage cluster UNC6508 compromised REDCap research servers across North American defense and medical institutions, then abused native Google Workspace content compliance rules to exfiltrate targeted emails without additional malware. The operation ran undetected for over two years, exposing gaps in supply-chain software maintenance and cloud configuration oversight. Evidence is drawn from GTIG reporting and known persistence techniques in similar campaigns.

The group first compromised REDCap servers used by US and Canadian medical research and defense entities. INFINITERED modified core system files to persist across upgrades, harvest credentials from the login page, and accept commands via HTTP cookies. Once inside, operators escalated to domain admin rights. Technical evidence consists of modified REDCap database tables containing stolen logins and the presence of the misspelled compliance rule named Patroit.

GTIG attributes the activity to a China-linked cluster with high confidence based on infrastructure overlap and targeting priorities that include uncrewed vehicles, offensive cyber tools, and chikungunya-related research. No specific CVE or initial access vector is named, and no independent technical attribution has been published. The method of using native Workspace content rules for exfiltration had not previously been observed from this actor.

This campaign fits an established pattern of state operators abusing legitimate cloud administration features rather than deploying custom mail malware. Similar rule-based forwarding has appeared in other suites, yet defenders rarely audit compliance configurations after initial setup. The persistence mechanism that survives REDCap upgrades highlights how legacy version coexistence creates downgrade opportunities.

Organizations should immediately audit all Workspace content compliance rules for unexpected BCC addresses and remove legacy REDCap installations. Continued monitoring of service account logins from research platforms is required; GTIG notifications have already disabled the attacker Gmail sink.

⚡ Prediction

GTIG: At least three additional North American REDCap instances will show INFINITERED artifacts within 120 days unless legacy versions are fully decommissioned.

Sources (3)

  • [1]
    Google Threat Intelligence Group UNC6508 Report(https://blog.google/threat-analysis-group/state-backed-attacks-defense-sector/)
  • [2]
    MITRE ATT&CK T1114.003 Email Forwarding Rule Abuse(https://attack.mitre.org/techniques/T1114/003/)
  • [3]
    The Hacker News Coverage of UNC6508 REDCap Campaign(https://thehackernews.com/2026/06/chinese-hackers-abused-google-workspace.html)