Last Updated: 2026-06-16T20:05:07Z
What’s Happening
Google Threat Intelligence Group has reported on a long-term espionage campaign against North American research and medical institutions using RedCAP, a common data collection/analysis tool.
RedCAP is quite common in research spaces. Per the report, a seemingly China-based attacker exploited an internet-facing RedCAP server, then remained on the system for two years (!), collecting information and credentials.
The INFINITERED malware used by the attackers compromised RedCAP update files and injected malware to maintain persistence in the PHP of the application across versions.
While INFINITERED is targeted specifically at the RedCAP application, it is reasonable to assume other similar technologies are also targeted. Given the stealth of this operation, it is also reasonable to assume multiple compromises have yet to be discovered.
Actions
If you operate RedCAP servers, initiate threat hunting and incident response procedures, including but not limited to the indicators listed in the GTIG report.
Take this opportunity to harden any public-facing web servers. Consider enhanced logging with tools like Kunai to enhance visibility.
Notes
The long dwell time on this system is really remarkable in this day and age, and speaks to the motivations of China-attributed operations. Destruction is not normally the goal. Instead, the objective is long-term information gathering. Consequently, highly stealthy techniques are more likely to be in play, including rootkits.
