A cyber espionage group linked to China secretly targeted research and defense organizations for more than a year. The attackers focused on medical, academic, and military institutions across North America. According to a recent report, they stole sensitive emails and research data. However, they used a less common method to avoid detection.
The attackers did not rely only on malware. Instead, they abused built-in email management features. Therefore, their activity blended into normal system operations. As a result, many organizations may not have noticed the theft right away.
How the Attack Started
The attack began with compromised REDCap servers. REDCap is a platform that many hospitals and universities use for research projects. Researchers found that the attackers targeted internet-facing REDCap systems. However, the exact method used for initial access remains unknown.
The group appeared to focus on older and potentially vulnerable installations. Therefore, organizations running outdated systems faced greater risks. After gaining access, the attackers spent months strengthening their position. As a result, they built a long-term presence inside victim networks.
Malware Hidden Inside REDCap
After entering the servers, the attackers deployed custom malware. Researchers named this malware INFINITERED. It modified trusted REDCap system files instead of adding obvious malicious programs. Therefore, it became much harder to detect.
The malware performed several key tasks. First, it collected usernames and passwords entered into login pages. Second, it stored the stolen credentials in encrypted database tables. Third, it created a hidden backdoor that accepted commands through web traffic. Moreover, the malware survived software updates. Whenever administrators installed a new version, the malicious code returned automatically. Therefore, normal update processes did not remove the threat.
Moving Through the Network
Once inside, the attackers explored internal systems. They searched for credentials and service accounts. Then, they used those accounts to move deeper into the network. Eventually, they obtained administrator-level access.
With higher privileges, the attackers gained broader visibility. Therefore, they could access valuable systems and resources. Researchers observed activity dating back to September 2023. However, the campaign continued until at least November 2025.
How Emails Were Stolen
The most unusual part of the operation involved email theft. Instead of installing email malware, the attackers abused existing cloud email features. Therefore, they avoided creating suspicious network activity.
The attackers modified content compliance rules. These rules normally help organizations monitor email content. However, the attackers used them to secretly copy messages. As a result, targeted emails were forwarded to an external mailbox.
Researchers found a rule with a misspelled name. The rule monitored nearly 150 keywords and email addresses. Therefore, only selected messages were copied. This approach helped the attackers focus on valuable information.
Targets of Interest
The keyword list revealed the attackers’ priorities. For example, they searched for military strategy and defense technologies. They also monitored advanced technology topics such as artificial intelligence and autonomous systems.
In addition, the attackers targeted medical research. One keyword related to a mosquito-borne disease outbreak. Therefore, the operation appeared highly focused and intelligence-driven. Researchers believe the stolen information supported broader espionage goals.
Why This Method Matters
This attack highlights a growing cybersecurity challenge. Attackers increasingly abuse legitimate features instead of deploying obvious malware. Therefore, traditional security tools may miss suspicious activity.
The email forwarding process looked like normal administration. As a result, network monitoring systems may not generate alerts. Furthermore, the attackers relied on trusted services already available inside the environment.
Researchers noted that similar email-forwarding abuse has appeared before. However, using content compliance rules in this way represents a notable evolution. Therefore, organizations must monitor cloud administration settings more closely.
Recommended Security Measures
Organizations should start by securing REDCap servers. For example, they should remove outdated versions and install the latest updates. Furthermore, administrators should regularly review exposed systems for weaknesses.
Security teams should also inspect email compliance and forwarding rules. Therefore, any unauthorized changes can be detected quickly. In addition, organizations should review audit logs to identify suspicious activity.
Strong multi-factor authentication is also essential. However, organizations should choose phishing-resistant methods for administrator accounts. As a result, attackers will face greater difficulty gaining privileged access.
How to Prevent Similar Attacks
To reduce the risk of similar threats, organizations should combine proactive monitoring with strong security controls. For example, continuous vulnerability assessments can identify exposed systems before attackers exploit them. In addition, managed detection and response services can monitor suspicious activity, unusual email rule changes, and unauthorized access attempts in real time.
Therefore, businesses can detect threats earlier, respond faster, and protect sensitive research, defense, and healthcare data from advanced cyber espionage campaigns.
Sleep well, we got you covered.

