China-linked actor spent two years inside medical research networks
ID: 58565dbe-29bd-52cf-92dc-206569847b5c
STIX ID: report--58565dbe-29bd-52cf-92dc-206569847b5c
Feed Name: Security Affairs
Google Threat Intelligence Group attributes a multi-year espionage campaign (Sep 2023–Nov 2025) to UNC6508, a China-linked actor that compromised REDCap servers at North American medical, academic, and military health organizations. The group deployed a custom REDCap-tailored backdoor called INFINITERED that persisted through upgrades, harvested credentials from logins, and used email forwarding rules to exfiltrate sensitive research and health-related communications; Google released a GTI indicator collection and assisted with remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
