Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
Chinese hackers exploited Google Workspace rules to steal sensitive research and defense emails from North American medical, academic, and military research networks. The attackers used a backdoor on REDCap research servers to gain access and then rewired the victims' Goo…
Intelligence analysis by Llama 3.3 70B

A China-linked espionage group used a REDCap backdoor to steal login credentials and then abused Google Workspace content compliance rules to exfiltrate sensitive emails, highlighting the need for organizations to review their mail rules and patch externally facing servers.
Imagine you have a mailbox where you receive sensitive emails, and someone finds a way to secretly copy those emails to their own mailbox. That's what happened here, where Chinese hackers used a special trick to copy emails from organizations in North America to their own inbox, without anyone noticing.
Analysis
The Chinese hackers, attributed to the UNC6508 group, compromised REDCap research servers using a custom malware called INFINITERED, which trojanized the system files and harvested usernames and passwords. The group then used the stolen credentials to gain admin access and set up a Google Workspace rule, dubbed 'Patroit,' to copy emails containing specific keywords to an attacker-controlled Gmail address. The rule was designed to watch for nearly 150 keywords, search terms, and email addresses, and the attackers used this feature to exfiltrate sensitive research and defense emails. The use of domain content compliance rules to exfiltrate emails is a new technique attributed to a China-linked actor, and it highlights the need for organizations to review their mail rules and patch externally facing servers. The incident also underscores the importance of securing cloud-based email services and the need for continuous monitoring and vigilance to detect and prevent such attacks. The attackers' use of a legitimate feature for malicious purposes demonstrates the evolving nature of cyber threats and the need for organizations to stay ahead of these threats by implementing robust security measures, such as phishing-resistant MFA on administrator accounts and regular audits of mail rules and admin access.
Key points
- Chinese hackers exploited Google Workspace rules to steal sensitive research and defense emails
- The attackers used a REDCap backdoor to gain access to the organizations' networks
- The incident highlights the importance of securing cloud-based email services and the need for continuous monitoring and vigilance
The incident highlights the importance of collaboration between organizations and security researchers to detect and prevent cyber threats. By sharing information and best practices, organizations can improve their security posture and reduce the risk of similar incidents. Additionally, the development of new security features and technologies can help to prevent such attacks in the future.
The incident demonstrates the sophistication and evolving nature of cyber threats, and the need for organizations to be vigilant and proactive in their security efforts. The use of legitimate features for malicious purposes highlights the challenges of detecting and preventing such attacks, and the potential consequences of a successful attack can be severe, including the theft of sensitive information and intellectual property.


