China Hackers Stole Defense Research via Gool
China-linked group used Google Workspace rules to steal defense research.
Model Diplomat7 min readNorth America

China's Hackers Turned Google's Own Tools Against It to Steal Defense Research
A China-linked espionage group spent 14 months inside North American research networks, using Google Workspace's built-in mail-filtering rules to silently copy sensitive emails, exposing a blind spot in every cloud suite that relies on legitimate admin features.
A China-linked espionage group hid inside North American medical, academic, and military research networks for more than 14 months, quietly exfiltrating sensitive research and defense correspondence by weaponizing a Google Workspace feature designed for compliance — not espionage. Google's Threat Intelligence Group (GTIG) attributed the campaign, detailed in a June 15, 2026 report, to a cluster it tracks as UNC6508, with high confidence. The technique turns every cloud email suite's administrative tooling into a potential exfiltration channel, and it is almost certainly being copied.
The Entry: REDCap as a Beachhead
The campaign's entry point was REDCap (Research Electronic Data Capture), a web platform hospitals and universities use to build and manage clinical study databases. REDCap is not a niche tool. According to consortium publications, it runs at over 7,730 institutions across 160+ countries and serves 3.6 million users, including the U.S. Department of Veterans Affairs, NIH-funded academic medical centers, and military health institutions Cambridge University Press. Its decentralized hosting model, where each institution installs and maintains its own instance, means patch discipline varies wildly across thousands of independent deployments.
UNC6508 compromised externally facing REDCap servers, though GTIG has not pinned down the precise initial-access vector or named a specific CVE The Hacker News. Roughly three months after gaining access, the group deployed custom malware GTIG calls INFINITERED, which trojanizes REDCap's own system files. INFINITERED does three things: it hijacks the upgrade process so each new REDCap version reinjects the malicious code; it harvests usernames and passwords from the login page, storing them encrypted in local database tables; and it functions as a backdoor, accepting commands through HTTP cookies and executing on every page load.
The earliest known compromise dates to September 2023, with activity continuing through November 2025. During that window, UNC6508 ran internal reconnaissance, pulled database and service-account credentials, and moved laterally until it reached a domain administrator account — the key that unlocked the mail exfiltration phase.
The Exfiltration: Compliance Rules as a Covert Channel
The most alarming element of the campaign was not the intrusion but the exit. Once UNC6508 held domain admin privileges, it created a Google Workspace content compliance rule, misspelled "Patroit," that monitored for nearly 150 keywords, search terms, and email addresses. When an incoming or outgoing message matched, Workspace silently BCC'd it to an attacker-controlled Gmail address, which Google has since disabled The Hacker News.
No malware sat on the mail server, no separate exfiltration tool generated anomalous network traffic, and no outbound data spike would have triggered a conventional DLP alert. The data left the organization through a feature that administrators routinely configure for legitimate purposes: scanning mail for regulated content like protected health information or export-controlled technical data, flowing through Google's own infrastructure.
MITRE's ATT&CK framework already catalogs email-forwarding-rule abuse as a known technique (T1098.007 in its actor-emulation matrix) Nature Scientific Reports. What GTIG flags as genuinely new is the use of domain-level content compliance rules, a broader, admin-tier capability distinct from per-user inbox rules, to achieve the same effect. GTIG says it had not previously seen a China-linked actor employ this method.
The keyword list mapped directly to UNC6508's collection priorities: geo-strategic policy, military strategy and equipment, advanced technology including AI and uncrewed vehicles, offensive cyber programs, and medical research. One term stood out for its specificity: chikungunya, the mosquito-borne virus behind a 2025 outbreak in China's Guangdong province. Its inclusion suggests the group was tasking against an active health-intelligence requirement, not merely casting a wide net.
Why REDCap Matters: A Diffuse, Hardened-Then-Forgotten Attack Surface
REDCap's ubiquity is precisely what makes it a strategic target. The platform is free to academic, nonprofit, and government organizations through the REDCap Consortium, licensed by Vanderbilt University Medical Center. But VUMC does not host or validate instances for consortium partners — each institution is responsible for its own deployment, patching, and compliance Cambridge University Press. A 2025 academic security analysis of research management applications explicitly modeled REDCap's vulnerabilities using the MITRE ATT&CK framework and STRIDE methodology, finding that its decentralized, highly configurable architecture creates an outsized attack surface for the sensitivity of the data it holds
arXiv.
REDCap also permits legacy versions to run alongside current builds — a design choice that enables so-called downgrade attacks, where an attacker forces the software back to a known-vulnerable release. GTIG's mitigation guidance is blunt: remove old versions outright, not just patch alongside the current build.
The UK's National Cyber Security Centre, in its guidance on reducing data exfiltration, identifies abuse of email as among the highest-priority exfiltration vectors and specifically lists "implementation of rules within products, apps and services" as a control surface that organizations must monitor NCSC. The UNC6508 campaign validates that concern with a real, attributed operation.
The Broader Pattern: China's Cyber Espionage as Industrial Policy
The UNC6508 campaign does not exist in isolation. It aligns with a documented pattern of China-nexus espionage targeting research, defense, and AI intellectual property. CrowdStrike's 2026 Technology Threat Landscape Report, published June 9, 2026, found that China-nexus adversaries drove more than 58% of state sponsored targeted intrusions against the technology sector in 2025, with MURKY PANDA's password-spraying campaign alone impacting over 340 U.S.-based entities CrowdStrike via FT.
That same week, the BBC reported that Anthropic accused Alibaba-linked operators of running nearly 29 million fraudulent exchanges against its Claude AI model — the largest distillation campaign on record — in a letter to U.S. Senators Tim Scott and Elizabeth Warren BBC. The White House had already issued a memo accusing foreign entities, principally China-based, of "industrial-scale campaigns" to extract U.S. AI capabilities
BBC. Separately, microsoft attributed SharePoint server compromises to China-linked groups Linen Typhoon and Violet Typhoon, targeting government, defense, and strategic-planning data
BBC.
What connects these operations is a consistent logic: China's state-linked apparatus is systematically acquiring capabilities and intelligence it cannot develop fast enough domestically. The UNC6508 campaign fits the pattern — medical and defense research exfiltrated through infrastructure the victims were already paying for.
The Governance Gap
The U.S. government's visibility into this threat depends on legal infrastructure that is itself fragile. The Cybersecurity Information Sharing Act of 2015 (CISA 2015), which provides the legal safe harbors that enable companies to share threat intelligence with government, was allowed to lapse in late 2025 before being temporarily restored through January 30, 2026, and then extended again on February 3, 2026, only through September of this year. One legislative staffer estimated that allowing the law to expire would result in "maybe an 80 to 90 percent reduction in cyber threat information flows" CNAS.
GTIG's own vice president, Sandra Joyce, testified before the House Committee on Homeland Security's Subcommittee on Cybersecurity and Infrastructure Protection on June 4, 2026, warning that adversaries are deploying AI to scale vulnerability discovery and that "exploits are the top attack vector" her team observes U.S. House of Representatives. Her testimony underscored that the AI software ecosystem — open-source wrapper libraries, API connectors, orchestration layers — has emerged as a primary exploitation target, with supply-chain compromises now a recurring vector.
Meanwhile, the Department of Defense's 2026 National Defense Strategy, released in February 2026, names deterring China in the Indo-Pacific as a core line of effort and explicitly calls for "adopting new advances in technology, like artificial intelligence" to maintain the defense industrial base's advantage U.S. DoD. The GAO reported in February 2026 that DOD requested nearly $180 billion for research, development, test, and evaluation activities in fiscal year 2026, including over $20 billion for science and technology — the very research base that campaigns like UNC6508 target
GAO.
The implication is direct: the research infrastructure the Pentagon is funding at record levels is being exfiltrated through the cloud productivity suites those same institutions use to collaborate.
Diplomat View
The UNC6508 campaign is a proof-of-concept for a class of attack that will proliferate. The technique of abusing built-in cloud compliance rules to silently reroute mail requires only domain admin access, which any sophisticated actor can obtain through credential harvesting on a single unpatched research server. Google Workspace is not uniquely vulnerable; equivalent admin-tier mail-filtering features exist in Microsoft 365 and other enterprise suites. The defense gap is not a missing product but a missing practice: organizations almost never audit content compliance and mail-forwarding rules for attacker-created entries, and admin-tier changes are rarely logged with the scrutiny applied to endpoint activity.
The forecast is straightforward. Within 12 months, at least one additional China-nexus cluster will be publicly attributed using an equivalent compliance-rule technique against a Microsoft 365 tenant, likely a defense contractor or federally funded research institution. The catalyst to watch is whether CISA 2015 is permanently reauthorized — and whether Congress modernizes it to explicitly cover cloud-administrative-rule abuse indicators — before its September 2026 expiration. If it lapses, the threat-intelligence sharing that surfaced UNC6508 in the first place degrades precisely as the technique spreads.
What to Watch Next
-
September 2026: CISA 2015 reauthorization deadline. If Congress allows the law to lapse, voluntary threat-intelligence sharing loses its legal safe harbors, degrading the detection pipeline that surfaced UNC6508.
-
Ongoing: GTIG has not identified the initial-access vector for the REDCap compromises. A CVE disclosure or advisory from the REDCap Consortium at Vanderbilt would be the first concrete step toward closing the beachhead.
-
House Homeland Security follow-through: Sandra Joyce's June 4 testimony flagged AI-enabled vulnerability discovery as the top attack vector. Watch for subcommittee follow-on hearings or a proposed legislative package addressing cloud-administrative-rule monitoring requirements.
The bottom line: UNC6508's innovation was not the breach — it was the exit. By turning Google Workspace's compliance rules into a silent mail-forwarding channel, China-linked hackers demonstrated that every cloud suite's legitimate administrative tooling is a covert exfiltration path waiting to be used. The organizations most at risk are the diffuse, under-patched research networks — REDCap's 7,730 institutions — that hold exactly the defense and biomedical intelligence Beijing is tasking its operators to collect.
Discover more

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

US Politics
House Ethics Committee Pushes Sexual Miscond.
The House Ethics Committee has shifted responsibility for sexual harassment settlement records to the Office of Congressional Workplace Rights, complicating disclosure efforts.

Economics
US Tariffs on Brazil: A Political Play
US imposes 25% tariff on Brazil but exempts 66% of exports, targeting manufactured goods ahead of Brazil's October election. Analysis of the political calculus, exemptions, and Brazil's response options.