Skip to content
← All Threat Actors
Nation-State high China (PRC)

UNC6508

Chinese state-sponsored (PRC-nexus, assessed with high confidence by Google TIG) · Espionage — biomedical research, defence technology, and public health intelligence collection

Reports 1
Active Since September 2023
Last Reported 18 Jun 2026
Sectors Targeted healthcare, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Exploitation of internet-facing REDCap research servers for initial access
  • INFINITERED custom implant deployment: functions simultaneously as dropper, credential harvester, and persistent backdoor
  • Credential harvesting via INFINITERED for lateral movement into broader institutional networks
  • Google Workspace content compliance rule abuse: configured forwarding rules on compromised accounts to silently exfiltrate emails matching target keywords to attacker-controlled Gmail addresses
  • Covert exfiltration via legitimate cloud administrative features to avoid C2 network detection
  • Long-duration, undetected presence (September 2023 – November 2025, 26+ months)

Known Targets

North American academic medical centres and clinical research organisationsNorth American military health institutionsProfessional advocacy groups and health regulatory bodiesInstitutions with molecular biology, drug discovery, clinical trial, and military medical readiness research

Analyst Notes

Disclosed by Google Threat Intelligence Group in June 2026. Collection priorities align with longstanding PRC state intelligence requirements: biomedical research, defence technology, and public health infrastructure. INFINITERED indicators of compromise published in the Google Cloud TIG disclosure.