Majority of Internet-Accessible REDCap Servers Outdated
The majority of internet-accessible REDCap servers are running outdated software versions, making them prime targets for state-sponsored threat actors, according to internet intelligence firm Censys.
A browser-based platform used for building and managing clinical research data in the medical field, REDCap is developed by Vanderbilt University and is used by academic, healthcare, and non-profit organizations.
According to a June report by Google’s Threat Intelligence Group (GTIG), legacy REDCap servers are routinely targeted by a China-linked threat actor tracked as UNC6508 for cyberespionage purposes.
Beginning in September 2023, as part of a campaign aimed at major medical, academic, and military research organizations in the US, the threat actor hacked web-facing REDCap servers and deployed custom malware for login credential harvesting.
In one instance, the attackers deployed the InfiniteRed backdoor three months after the initial intrusion. One year after remaining undetected, the hacking group used the harvested credentials to access the organization’s...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE