Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
June 16, 2026, 11:48 a.m.
Description
A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection requirements.
Tags
Date
- Created: June 15, 2026, 7:33 p.m.
- Published: June 15, 2026, 7:33 p.m.
- Modified: June 16, 2026, 11:48 a.m.
Indicators
- ba6b73b0ca0dc7f86b3b397893ac32d729fd53f9df20643288f141f29d020af7
- 4efbef69eb3b09bacff892d6a55778d07c418e7f15eba3cf1245e8cdfd8dda0b
- 51a57bfc9ed3eb6451c1c289607814d59e1698c666fb97ac5f694c398f23d045
- 8f0158855a656b629ca76ebca565f18bc25563ded34b65d6771632c20edb68ec
- 58bb25777e0aa86bcd2125101e0bca4e8732b03d91bd8d2f205b446a2a8d5c86
- c1ac43d23f89d41eb4ff131678ab562ab2cfed9aa334b13767ef141d303b0e5b
- db65c1b9f9e4cb4d729f45ad4b6fcf3e277caf9eb4c875425dec93fd883f9136
- 23.169.65.49
Additional Informations
- Education
- Defense
- Healthcare
- Government
- Canada
- United States of America