CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

June 25, 2026

A China-linked espionage group tracked as UNC6508 compromised REDCap research servers across North American medical, academic, and military institutions, stealing sensitive research and defense emails by abusing Google Workspace content compliance rules. The group deployed custom malware INFINITERED to harvest credentials and maintain persistence, then used domain admin access to create a rule that silently BCC’d matching emails to an attacker-controlled Gmail address. Google’s Threat Intelligence Group (GTIG) disclosed the campaign, noting activity from September 2023 through November 2025. The exfiltration method—using built-in mail features rather than malware—represents a novel technique for China-linked actors. Defenders are advised to patch REDCap servers, audit Workspace mail rules, and implement phishing-resistant MFA on admin accounts.

CVEs: CVE-2026-11645

Attack groups: UNC6508

Malware: INFINITERED

Companies: Google

Products: Google Workspace, REDCap