logo

China-linked UNC6508 Espionage Campaign Targets US and Canadian Research Institutions

ID: 11965556-7025-5562-bb7b-0d18062185f0

STIX ID: report--11965556-7025-5562-bb7b-0d18062185f0

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-17

...
...

UNC6508, a China-linked threat actor, conducted a multi-year campaign (Sep 2023–Nov 2025) targeting North American academic, medical, and military research institutions by exploiting REDCap server vulnerabilities to steal credentials and sensitive research data. The group used custom malware called Infinitered for persistence and exfiltration and automated email forwarding via Google Workspace content compliance rules to siphon targeted emails to attacker-controlled accounts; Google later disrupted the operation and notified affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.