Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
ID: 37e3ede2-e5af-5f3e-a3ad-cf5b21e9f026
STIX ID: report--37e3ede2-e5af-5f3e-a3ad-cf5b21e9f026
Feed Name: Google Cloud Threat Intelligence
GTIG attributes a multi-year, highly targeted campaign to UNC6508 (a PRC‑nexus actor) that exploited externally facing REDCap servers to deploy custom INFINITERED malware, harvested credentials, pivoted to privileged accounts, and abused admin/content compliance rules to covertly exfiltrate sensitive research and defense-related data from North American medical, academic, and military research organizations; GTIG disrupted the infrastructure, engaged Mandiant, notified victims, and published mitigation recommendations and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
