discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

Chinese hackers exploited Google Workspace rules to steal sensitive research and defense emails from North American medical, academic, and military research networks. The attackers used a backdoor on REDCap research servers to gain access and then rewired the victims' Goo…

By Swati Khandelwal·Jun 15·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
Image: thehackernews.com

A China-linked espionage group used a REDCap backdoor to steal login credentials and then abused Google Workspace content compliance rules to exfiltrate sensitive emails, highlighting the need for organizations to review their mail rules and patch externally facing servers.

Why it matters

This incident highlights the importance of securing cloud-based email services and the need for organizations to be aware of the risks associated with using legitimate features for malicious purposes. The abuse of Google Workspace rules by Chinese hackers demonstrates the evolving nature of cyber threats and the need for continuous monitoring and vigilance.

Imagine you have a mailbox where you receive sensitive emails, and someone finds a way to secretly copy those emails to their own mailbox. That's what happened here, where Chinese hackers used a special trick to copy emails from organizations in North America to their own inbox, without anyone noticing.

Analysis

The Chinese hackers, attributed to the UNC6508 group, compromised REDCap research servers using a custom malware called INFINITERED, which trojanized the system files and harvested usernames and passwords. The group then used the stolen credentials to gain admin access and set up a Google Workspace rule, dubbed 'Patroit,' to copy emails containing specific keywords to an attacker-controlled Gmail address. The rule was designed to watch for nearly 150 keywords, search terms, and email addresses, and the attackers used this feature to exfiltrate sensitive research and defense emails. The use of domain content compliance rules to exfiltrate emails is a new technique attributed to a China-linked actor, and it highlights the need for organizations to review their mail rules and patch externally facing servers. The incident also underscores the importance of securing cloud-based email services and the need for continuous monitoring and vigilance to detect and prevent such attacks. The attackers' use of a legitimate feature for malicious purposes demonstrates the evolving nature of cyber threats and the need for organizations to stay ahead of these threats by implementing robust security measures, such as phishing-resistant MFA on administrator accounts and regular audits of mail rules and admin access.

Key points

  • Chinese hackers exploited Google Workspace rules to steal sensitive research and defense emails
  • The attackers used a REDCap backdoor to gain access to the organizations' networks
  • The incident highlights the importance of securing cloud-based email services and the need for continuous monitoring and vigilance
The Upside

The incident highlights the importance of collaboration between organizations and security researchers to detect and prevent cyber threats. By sharing information and best practices, organizations can improve their security posture and reduce the risk of similar incidents. Additionally, the development of new security features and technologies can help to prevent such attacks in the future.

The Downside

The incident demonstrates the sophistication and evolving nature of cyber threats, and the need for organizations to be vigilant and proactive in their security efforts. The use of legitimate features for malicious purposes highlights the challenges of detecting and preventing such attacks, and the potential consequences of a successful attack can be severe, including the theft of sensitive information and intellectual property.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscyber-espionageemail-securitygoogle-workspacemalwaresecurity

Author

Swati Khandelwal

Intelligence analysis by

Llama 3.3 70B

Published

Jun 15, 2026

Source

thehackernews.com

Share

Topics

cyber-espionageemail-securitygoogle-workspacemalwaresecurity

Related

More from this desk

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.

Oct 7·krebsonsecurity.com

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Jordanian teenager detained for leading ShinyHunters, a data theft and extortion group. FBI investigating extortion of Boeing subsidiary Jeppesen ForeFlight.

Oct 7·schneier.com

Apple’s Verified Photography System

Apple introduces a new system called 'Reference Image' to verify iPhone photos without tying them to specific devices or photographers.