logo

China-Nexus Actor Spy on US Researchers Undetected for a Year

ID: 29ce13c3-f86f-5f74-af4d-b806ee22cc73

STIX ID: report--29ce13c3-f86f-5f74-af4d-b806ee22cc73

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: Elizabeth Montalbano

...
...

Google Threat Intelligence Group and Mandiant uncovered and disrupted UNC6508, a China-aligned APT that covertly spied on US academic, medical, and military research organizations from at least September 2023 through November 2025. The actor exploited externally facing REDCap servers, deployed a custom credential-stealing malware called Infinitered tailored to REDCap, escalated to domain administrator access, and used a novel content-compliance rule method to forward sensitive emails to actor-controlled accounts; the campaign used US-based IP infrastructure for obfuscation. GTIG and Mandiant notified affected organizations, provided IOCs, and recommended enforcing phishing-resistant MFA, monitoring audit logs, enabling DLP, and patching systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.