Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

June 16, 2026, 11:48 a.m.

Description

A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection requirements.

Date

  • Created: June 15, 2026, 7:33 p.m.
  • Published: June 15, 2026, 7:33 p.m.
  • Modified: June 16, 2026, 11:48 a.m.

Indicators

  • ba6b73b0ca0dc7f86b3b397893ac32d729fd53f9df20643288f141f29d020af7
  • 4efbef69eb3b09bacff892d6a55778d07c418e7f15eba3cf1245e8cdfd8dda0b
  • 51a57bfc9ed3eb6451c1c289607814d59e1698c666fb97ac5f694c398f23d045
  • 8f0158855a656b629ca76ebca565f18bc25563ded34b65d6771632c20edb68ec
  • 58bb25777e0aa86bcd2125101e0bca4e8732b03d91bd8d2f205b446a2a8d5c86
  • c1ac43d23f89d41eb4ff131678ab562ab2cfed9aa334b13767ef141d303b0e5b
  • db65c1b9f9e4cb4d729f45ad4b6fcf3e277caf9eb4c875425dec93fd883f9136
  • 23.169.65.49

Attack Patterns

Additional Informations

  • Education
  • Defense
  • Healthcare
  • Government
  • Canada
  • United States of America