UNC6508 is a China-linked espionage group targeting North American research institutions.
Analyst brief
UNC6508 is a threat actor with assessed ties to China, conducting espionage operations against North American academic, medical, and military research institutions. The actor exploits REDCap servers and deploys custom “INFINITERED” malware, while using a “help.php” web shell for persistence and manipulating email compliance rules to exfiltrate sensitive communications to a Gmail account. Defenders should prioritize monitoring for anomalous authentication attempts on research platforms like REDCap, inspecting for unauthorized web shells, and auditing email forwarding rules on sensitive accounts to detect covert exfiltration.
UNC6508
unknown
UNC6508 is a PRC-nexus threat actor targeting North American academic, medical, and military research institutions, employing tactics such as exploiting REDCap servers and deploying custom malware named INFINITERED. The actor utilized credential harvesting, internal reconnaissance, and a web shell named "help.php" for persistence. They also manipulated content compliance rules for covert data exfiltration, forwarding sensitive email communications to a threat actor-controlled Gmail address. GTIG attributes this espionage activity to UNC6508 with high confidence, based on infrastructure overlaps and specific targeting of defense and medical research sectors.