INFINITERED is a custom modular PHP backdoor used by the China-linked espionage cluster UNC6508 in long-running intrusions against internet-exposed REDCap servers. It has been observed in campaigns targeting North American medical, academic, military, and broader research organizations, with collection priorities aligned to sensitive medical research, defense, advanced technology, and geopolitical intelligence requirements.
The malware is tailored specifically for REDCap environments and achieves persistence by trojanizing legitimate REDCap system files. Its most notable persistence mechanism intercepts the REDCap software upgrade process and reinjects malicious code into newly installed versions, allowing the compromise to survive routine application updates and maintain long-term remote access. INFINITERED has also been described as operating through multiple modular components, including persistence or upgrade-interception logic, a credential harvester, and a backdoor.
INFINITERED captures usernames and passwords submitted through REDCap login portals and stores the stolen credentials locally in encrypted form for later retrieval. Its backdoor component executes during normal page loads and accepts commands delivered through HTTP cookies. Reported capabilities include beaconing host and application details, executing shell commands, running arbitrary SQL queries, transferring files, and retrieving harvested credentials. These functions supported follow-on intrusion activity by UNC6508, including lateral movement from compromised REDCap infrastructure into internal environments and eventual abuse of administrative email controls for covert data exfiltration.
Observed deployments followed compromise of externally facing REDCap servers, often after the actor probed legacy or vulnerable REDCap versions. INFINITERED has been consistently associated with UNC6508 and is a defining malware component of that actor’s REDCap-focused espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC6508 compromised REDCap servers to engage in credential theft using INFINITERED and covertly exfiltrate emails.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
More than a year after the initial compromise, the threat actor used credentials stolen from REDCap to log into an administrator account and modified content compliance rules.
It compromised external facing web applications... The problem is those older versions still had known remote code execution vulnerabilities, and they’re sitting on the same server, still internet-facing. UNC6508 probed for those legacy versions specifically.
When non-empty, the malware will parse the payload for command tags, which the threat actor can use to execute shell commands, run raw SQL queries and transfer files.
More than a year after the initial compromise, the threat actor used credentials stolen from REDCap to log into an administrator account and modified content compliance rules.
In one instance, the attackers deployed the InfiniteRed backdoor three months after the initial intrusion.
UNC6508 exploited a public-facing REDCap server to drop a webshell and deploy INFINTERED malware, a PHP backdoor. | While the initial access method is currently unconfirmed, UNC6508 exploited a public-facing REDCap server to drop a webshell and deploy INFINTERED malware, a PHP backdoor.
Credential Harvester: Captures plaintext usernames and passwords from POST login requests, encrypts them, and stores them covertly in the REDCap sessions database under the prefix xc32038474a.
After establishing a foothold, the attackers conducted network reconnaissance, collected database and service account credentials...
Kimsuky used malicious LNK files, the Dropbox API, GitHub Releases, and Google Drive for Information Theft and command execution.
The backdoor lived in the custom hooks system file inside the update package and ran on every page load. It looked for a specific HTTP cookie containing an encrypted payload, allowing attackers to communicate with the malware and issue commands.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-theft malware used after REDCap server compromise, with covert email exfiltration.
A custom backdoor deployed by UNC6508 after compromising internet-facing REDCap servers, used to maintain access following initial intrusion in cyberespionage operations.
Custom malware used by UNC6508 against REDCap servers. It embeds itself into REDCap’s upgrade workflow so that when institutions upgrade to patched versions, the malware survives and re-infects the new version, enabling long-term persistence on compromised servers.
Custom PHP backdoor used to maintain long-term access to compromised REDCap servers, support data exfiltration, and enable deployment of additional malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.