logo

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

ID: 37e3ede2-e5af-5f3e-a3ad-cf5b21e9f026

STIX ID: report--37e3ede2-e5af-5f3e-a3ad-cf5b21e9f026

Feed Name: Google Cloud Threat Intelligence

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Google Threat Intelligence Group

...
...

GTIG attributes a multi-year, highly targeted campaign to UNC6508 (a PRC‑nexus actor) that exploited externally facing REDCap servers to deploy custom INFINITERED malware, harvested credentials, pivoted to privileged accounts, and abused admin/content compliance rules to covertly exfiltrate sensitive research and defense-related data from North American medical, academic, and military research organizations; GTIG disrupted the infrastructure, engaged Mandiant, notified victims, and published mitigation recommendations and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.