Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
For over a year, a China-affiliated espionage outfit surreptitiously stole confidential research and defense emails from North American medical, academic, and military research networks.
A backdoor on their REDCap research servers was used to gain access and steal login information. The interesting portion was the exfiltration, where the attackers copied each communication that matched their keywords to an inbox they controlled by rewiring the victims' own Google Workspace policies.
In a study released this week, Google's Threat Intelligence Group (GTIG) described the effort and highly confidently linked it to a cluster it monitors as UNC6508.
Google initially mentioned the actor and its REDCap backdoor in a broader study on state-sponsored attacks on the defense industry in Febr...





