Chinese Hackers Used Hidden Mail Rules to Steal Data
A cyber espionage group linked to China secretly targeted research, medical, and defense organizations. The attackers stayed hidden for more than a year. As a result, they collected sensitive emails and research information. According to a recent report, the campaign affected several organizations across North America. Therefore, security teams now face a growing challenge from stealthy email theft methods.
The attackers focused on institutions involved in healthcare, academics, and defense research. However, they did not rely only on malware. Instead, they used trusted systems already present inside the victims’ environments. This approach helped them avoid detection for a long time.
How the Attack Started
The attackers first targeted REDCap servers. Many hospitals and universities use this platform to manage research data. According to researchers, the group compromised internet-facing REDCap systems. However, investigators have not confirmed the exact entry method.
The attackers appeared to focus on older and potentially vulnerable server versions. After gaining access, they quietly expanded their control. Therefore, they were able to remain inside targeted networks for extended periods.
Several months later, the group installed custom malware called INFINITERED. This malware modified system files and created a hidden backdoor. As a result, the attackers could maintain access even after updates occurred. The malware also captured usernames and passwords from login pages. Furthermore, it stored stolen credentials in encrypted database tables. Therefore, the attackers could gather valuable access information without raising suspicion.
Building Long-Term Access
After compromising the servers, the attackers explored internal systems. They searched for service accounts and privileged credentials. As a result, they gained deeper access across the network.
The group eventually obtained administrator-level permissions. Therefore, they could move freely between systems and access sensitive resources. Researchers believe this phase lasted for many months.
The earliest known activity began in September 2023. However, the operation continued until at least November 2025. This long timeframe highlights how difficult such attacks can be to detect.
How Emails Were Secretly Stolen
Instead of deploying new email malware, the attackers used existing mail features. They abused content compliance rules available in cloud email services. Therefore, they could collect emails without creating unusual network activity.
These rules normally help organizations monitor sensitive communications. However, the attackers changed them for malicious purposes. As a result, targeted emails were silently copied to accounts they controlled.
Researchers found a suspicious rule named “Patroit.” The rule monitored nearly 150 keywords, email addresses, and search terms. Therefore, any matching email automatically triggered a hidden copy. The copied messages went to an attacker-controlled inbox. Furthermore, the process happened without user awareness. As a result, organizations lost sensitive information while seeing no obvious warning signs.
What Information Was Targeted
The attackers focused on valuable strategic information. For example, they searched for military planning details and defense technologies. They also targeted advanced technologies such as artificial intelligence and autonomous systems.
Medical research was another major target. Furthermore, researchers observed interest in disease-related topics and public health information. Therefore, the campaign likely supported broad intelligence-gathering goals. The keyword list revealed highly specific collection priorities. For example, one keyword related to a mosquito-borne virus linked to a recent outbreak. Such details suggest the attackers carefully selected their targets.
This campaign demonstrates how attackers can abuse trusted tools. Instead of creating noisy malware, they used legitimate features. Therefore, traditional security monitoring may miss such activity. The attack also shows the importance of securing research platforms. Once attackers gained administrator access, they could exploit built-in email functions. As a result, sensitive information flowed directly to external accounts.
Researchers noted that this technique differs from many previous espionage operations. However, it highlights a growing trend toward abusing cloud administration features. Therefore, organizations must monitor configuration changes more closely.
How to Prevent Similar Attacks
Organizations should regularly update research platforms and remove outdated software versions. Furthermore, security teams should review mail forwarding and compliance rules for unauthorized changes. Continuous security monitoring can also help detect unusual administrator activity before major damage occurs. In addition, managed detection and response services can identify hidden threats across networks. Regular vulnerability assessments and security hardening programs can further reduce the risk of unauthorized access and long-term persistence.
Sleep well, we got you covered.

