Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Incidents & Breaches Google Cloud

China-Linked Hackers Spent Over a Year Inside US Medical Research Networks

Google's threat intelligence team has exposed a prolonged espionage campaign by a PRC-affiliated group that used REDCap vulnerabilities and a novel email-forwarding trick to quietly siphon sensitive medical and defense research data.

China-Linked Hackers Spent Over a Year Inside US Medical Research Networks
Tima Miroshnichenko · Pexels

Google Threat Intelligence Group (GTIG) and Mandiant Consulting have jointly disrupted an espionage operation tied to UNC6508, a threat cluster assessed with high confidence to be aligned with People's Republic of China intelligence priorities. The campaign ran from at least September 2023 through November 2025, targeting organizations across the US and Canada whose combined research budgets run into the billions of dollars.

What happened

Attackers initially gained access by exploiting externally accessible REDCap servers — a web-based platform widely used in academic and clinical research for managing surveys and databases. GTIG was unable to confirm the precise exploitation method, but observed the group probing for legacy software versions left running alongside current installations, a permitted REDCap configuration that creates a downgrade-attack surface.

Three months after establishing a foothold, UNC6508 deployed a custom malware family called INFINITERED by trojanizing legitimate REDCap system files. The malware operates across three components: a dropper that intercepts REDCap's own upgrade process to reinject malicious code into each new version, a credential harvester that captures POST-submitted login data and stores it encrypted inside a legitimate database table, and a backdoor that activates via a specially crafted HTTP cookie named REDCAP-TOKEN. INFINITERED can execute shell commands, run arbitrary SQL queries, transfer files, and beacon system details including database credentials back to the operator.

More than a year after the initial breach, the group replayed harvested credentials to access a domain administrator account, then created a content compliance rule — a standard feature in cloud productivity suites — named "Patroit" (the misspelling appears in the original rule). The rule used regular expressions to match emails containing keywords tied to geopolitical, military, medical, and technology topics, silently BCC-forwarding matches to a threat-actor-controlled Gmail address. GTIG subsequently disabled that account.

Key facts
  • Earliest confirmed compromise: September 2023; activity observed through November 2025
  • Targets included clinical providers, academic centers, military health bodies, and health regulators in the US and Canada
  • INFINITERED persisted across REDCap upgrades for more than a year before detection
  • Exfiltration routed through US-based obfuscation networks using compromised routers and residential proxies
  • Compliance rule keyword list included the specific pathogen Chikungunya, which caused a 2025 outbreak in China's Guangdong province

Why it matters

The use of email compliance rules for covert data exfiltration marks a tactic not previously documented among PRC-linked actors, according to GTIG. By abusing a legitimate administrative feature rather than deploying additional tooling, UNC6508 avoided triggering security controls that focus on anomalous software behavior. The group also maintained operational security by routing all activity through US-hosted infrastructure — compromised consumer routers, residential proxies, and VPS nodes — making geographic attribution harder for defenders relying on IP geolocation.

The breadth of collection interests documented in the "Patroit" rule suggests UNC6508's actual target list may extend well beyond the institutions GTIG was able to identify. Intelligence priorities reflected in the keyword patterns include Indo-Pacific military posture, uncrewed vehicle programs, offensive cyber capabilities, and medical research — areas consistent with documented PRC state-sponsored collection requirements.

What to watch

GTIG has pushed indicators of compromise and detections into Google Security Operations and published YARA rules for identifying INFINITERED on REDCap servers. Organizations running REDCap should treat any legacy software version left in place as an active risk surface and prioritize removal alongside patching. The group recommends phishing-resistant two-step verification on all administrator accounts, enforcement of Device Bound Session Credentials on sensitive Windows endpoints, and a manual audit of existing email compliance rules for unauthorized modifications.

The specific inclusion of Chikungunya-related terms in the exfiltration keyword list, timed against a real outbreak in China, points to an actor with current operational tasking rather than one operating from a static collection template — a detail defenders tracking PRC health-related espionage should factor into threat modeling.

For professionals

For professionals: Audit all content compliance or mail-routing rules in your cloud productivity tenant immediately — this vector requires no malware on end-user devices and leaves minimal logs by default. Ensure REDCap deployments run only the current version, with legacy installations fully removed, and scan web-accessible servers using the YARA rule GTIG has published.

Companies mentioned

Google Cloud

Discussion · coming soon

Be the first to join the thread when community discussion launches.