Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
Essential information
- Published
- 15/06/2026 19:33
- Modified
- 16/06/2026 11:48
- Tags
- 2026-06-15 china-nexus content compliance abuse credential harvesting email-exfiltration infinitered medical research targeting redcap exploitation unc6508
- Related entities
- 8 observables, 1 intrusion sets (apt), 12 techniques (mitre), 1 malware, 6 others
Description
A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection requirements.