← All Threat Actors
UNC6508
Chinese state-sponsored (PRC-nexus, assessed with high confidence by Google TIG) · Espionage — biomedical research, defence technology, and public health intelligence collection
Reports 1
Active Since September 2023
Last Reported 18 Jun 2026
Sectors Targeted healthcare, critical-infrastructure
Tactics, Techniques & Procedures (TTPs)
- Exploitation of internet-facing REDCap research servers for initial access
- INFINITERED custom implant deployment: functions simultaneously as dropper, credential harvester, and persistent backdoor
- Credential harvesting via INFINITERED for lateral movement into broader institutional networks
- Google Workspace content compliance rule abuse: configured forwarding rules on compromised accounts to silently exfiltrate emails matching target keywords to attacker-controlled Gmail addresses
- Covert exfiltration via legitimate cloud administrative features to avoid C2 network detection
- Long-duration, undetected presence (September 2023 – November 2025, 26+ months)
Known Targets
North American academic medical centres and clinical research organisationsNorth American military health institutionsProfessional advocacy groups and health regulatory bodiesInstitutions with molecular biology, drug discovery, clinical trial, and military medical readiness research
Analyst Notes
Disclosed by Google Threat Intelligence Group in June 2026. Collection priorities align with longstanding PRC state intelligence requirements: biomedical research, defence technology, and public health infrastructure. INFINITERED indicators of compromise published in the Google Cloud TIG disclosure.
MITRE ATT&CK Techniques
T1190 Exploit Public-Facing Application (REDCap) T1587.001 Develop Capabilities: Malware (INFINITERED) T1078 Valid Accounts (harvested credentials for lateral movement) T1114.003 Email Collection: Email Forwarding Rule (Google Workspace abuse) T1020 Automated Exfiltration via compliance rule forwarding