logo

China-linked actor spent two years inside medical research networks

ID: 58565dbe-29bd-52cf-92dc-206569847b5c

STIX ID: report--58565dbe-29bd-52cf-92dc-206569847b5c

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Pierluigi Paganini

...
...

Google Threat Intelligence Group attributes a multi-year espionage campaign (Sep 2023–Nov 2025) to UNC6508, a China-linked actor that compromised REDCap servers at North American medical, academic, and military health organizations. The group deployed a custom REDCap-tailored backdoor called INFINITERED that persisted through upgrades, harvested credentials from logins, and used email forwarding rules to exfiltrate sensitive research and health-related communications; Google released a GTI indicator collection and assisted with remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.