Skip to content
EspionageContained

UNC6508 PRC-nexus medical & defense research espionage campaign

Google's Threat Intelligence Group disclosed that PRC-nexus actor UNC6508 spent more than a year inside U.S. and Canadian medical, academic and military-health research environments, compromising legacy REDCap servers, deploying custom INFINITERED malware and abusing Google Workspace email compliance rules to silently exfiltrate research and defense data.

Victim
U.S. and Canadian medical, academic and military-health research institutions

On 15 June 2026, Google's Threat Intelligence Group (GTIG) β€” Google's threat-research arm β€” disclosed a multiyear cyber-espionage campaign by UNC6508, a threat cluster it attributes with high confidence to People's Republic of China (PRC) state intelligence interests. The campaign quietly burrowed into a diverse set of U.S. and Canadian medical, academic and military-health research organisations β€” clinical providers, premier academic medical centres, North American military health institutions, professional advocacy groups and health regulatory bodies β€” and remained undetected for more than a year.

GTIG dated the earliest known compromise to September 2023, with malicious activity continuing consistently through November 2025. The campaign's strategic focus spanned national-security and defense research (Indo-Pacific command operations, uncrewed-vehicle systems, AI and offensive-cyber programmes) as well as medical research (clinical drug trials, molecular discovery, and work on the Chikungunya pathogen linked to a 2025 outbreak in China's Guangdong province).

How the intrusion worked

UNC6508 consistently targeted REDCap servers β€” a web-based platform widely used by universities and hospitals to build and manage research databases and surveys in compliance with medical-research regulations. The actor exploited vulnerable legacy versions of REDCap to gain a foothold, then planted a help.php web shell for persistence and file upload.

Roughly three months after initial access β€” a deliberately patient, low-noise approach β€” UNC6508 deployed a custom modular implant GTIG named INFINITERED. Its three components handled (1) dropping and intercepting REDCap software upgrades so the malware persisted across updates, (2) harvesting credentials, encrypting them with the environment's own routine and hiding them inside a local REDCap sessions database table, and (3) a backdoor with command-and-control supporting arbitrary shell commands, SQL queries, and file upload/download.

Living-off-the-cloud exfiltration

The campaign's most notable tradecraft came after more than twelve months of patience: UNC6508 used harvested credentials to reach a Google Workspace administrator account and then abused a legitimate email security feature β€” content-compliance rules β€” for covert data exfiltration. The actor created a compliance rule (misspelled "Patroit") that used regular expressions to match keywords and email-address patterns, then silently BCC-forwarded matching messages to an attacker-controlled Gmail address. Google disabled the account upon discovery.

To stay hidden, UNC6508 routed its operations through obfuscation networks β€” a mix of compromised routers (including a compromised ASUS router), residential proxies and VPS infrastructure β€” relying exclusively on U.S.-based egress IPs for outbound connections.

Why it matters

The campaign is a textbook case of patient, state-sponsored collection against the research base rather than a smash-and-grab data theft. It underscores three recurring lessons: that internet-exposed legacy research software like unpatched REDCap remains an attractive initial-access vector; that abusing legitimate cloud-native features (Workspace compliance rules, upgrade mechanisms) lets attackers blend into normal administration and evade detection for years; and that medical and academic research environments, often under-resourced for security but rich in defense-adjacent intellectual property, are squarely in the sights of nation-state actors. GTIG urged affected sectors to enforce 2-Step Verification on admin accounts, patch and remove legacy REDCap versions, and audit Workspace compliance rules for unauthorised modifications.

Timeline

  1. Earliest known UNC6508 compromise observed by Google's Threat Intelligence Group (GTIG): the actor exploits externally-facing, vulnerable legacy REDCap research servers and plants a 'help.php' web shell for persistence.

  2. Roughly three months after initial access, UNC6508 deploys the custom modular INFINITERED malware β€” a dropper with upgrade-interception, a credential harvester, and a C2 backdoor β€” to capture REDCap logins while surviving software updates.

  3. GTIG observes the credential-harvesting activity continuing consistently through November 2025; harvested credentials are later used to reach internal networks and Google Workspace administrator accounts.

  4. GTIG publishes its report attributing the multiyear campaign to PRC-nexus cluster UNC6508 and detailing the abuse of Workspace email content-compliance rules for covert exfiltration.

Sources

  1. cloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research
  2. darkreading.comhttps://www.darkreading.com/threat-intelligence/china-nexus-actor-us-researchers-undetected
  3. csoonline.comhttps://www.csoonline.com/article/4185582/china-linked-hackers-target-us-canada-research-using-legacy-redcap-exploits.html
  4. cybersecuritydive.comhttps://www.cybersecuritydive.com/news/china-nexus-multiyear-hacking-us-canadian-medical-research/822912/

Related incidents