Monday’s Google Threat Intelligence report got a fraction of the attention it earned.
Call it Salt Typhoon Jr.: a PRC-linked group sat inside North American military research and medical networks for more than a year, undetected, and walked out with the research that decides who wins the next decade.
It was easy to miss under the flood of Mythos, Fable, and zero-days-for-days coverage. (Which tells you we still rank threats by how frightening they sound to a general audience, not by what they cost national security.)
GTIG tracks the group as UNC65081. Their collection list reads like a tasking order: nearly 150 keywords spanning:
Defense intelligence
Indo-Pacific operations
Artificial intelligence (AI)
Uncrewed systems
Cyber offensive programs
Medical research
This was public-health surveillance running inside a military espionage campaign, out of the same institutions, on the same wire.
The exfiltration method should stop every Workspace admin cold. The attackers used a Google Workspace content-compliance rule to silently BCC matching emails to a Gmail account they controlled.
Any operator can copy that playbook tomorrow against every university, hospital, and defense contractor running Workspace.
Three places AI would have helped:
Admin control-plane monitoring. A brand-new rule that BCC-forwards sensitive mail to a consumer Gmail account should trip an alert the day it is created. That is pattern-spotting across thousands of admin events, which is what a model is good for.
Cross-victim correlation. The same campaign hit multiple organizations at once, and each intrusion looked isolated because nobody had visibility across all of them. Correlation across organizations, identity providers, and SaaS logs could have surfaced the pattern months earlier.
Behavioral EDR over the dwell window. INFINITERED sat on the REDCap server for more than a year, harvesting credentials, before the attackers used them to pivot into the internal network. That is a long baseline, long enough for behavior-based detection to flag a novel dropper and its callbacks even on malware nobody had seen before. (In theory. In practice, most shops never tuned the baseline.)
Attacker Stealth: These operators knew what defenders watch and stayed under it. They used legitimate credentials, kept operational security tight, and ran nothing noisy.
High Environmental Noise. Defining a baseline for an AI model in this specific environment is nearly impossible. Teaching any model what “normal” looks like inside a military health research institution, across clinicians, researchers, contractors, and classified projects, is hard.
AI Finds Outliers. It does not fix bad access design, or an organization that will not lock things down.
Audit your mail rules. Google Workspace, Microsoft 365, anything with message-handling rules. Look for rules you did not create, destinations you do not recognize, and conditions that quietly match your sensitive projects.
Treat SaaS admin config as a controlled asset. Approvals, alerts, and a regular review on every admin change, the same way you would treat a firewall rule.
Patch REDCap, and assume patching is not enough. The initial access vector is still unconfirmed publicly, but INFINITERED was engineered to reinject itself through REDCap’s upgrade process. A patch dropped on a compromised server is not a clean server. Rebuild, then patch. That logic applies to every “we’ll keep the old version for one project” exception in your environment.
This ran for over two years inside medical and military research networks before anyone caught it. The detection tooling we are all paying for did not see a two-year intrusion.
Rob T. Lee is Chief AI Officer & Chief of Research, SANS Institute

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.