China-linked UNC6508 Espionage Campaign Targets US and Canadian Research Institutions
ID: 11965556-7025-5562-bb7b-0d18062185f0
STIX ID: report--11965556-7025-5562-bb7b-0d18062185f0
Feed Name: ThreatCluster
UNC6508, a China-linked threat actor, conducted a multi-year campaign (Sep 2023–Nov 2025) targeting North American academic, medical, and military research institutions by exploiting REDCap server vulnerabilities to steal credentials and sensitive research data. The group used custom malware called Infinitered for persistence and exfiltration and automated email forwarding via Google Workspace content compliance rules to siphon targeted emails to attacker-controlled accounts; Google later disrupted the operation and notified affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
