Skip to main content
Mallory
🇨🇳 CN2 malware families

UNC6508

Also known asUNC6508

UNC6508 is a PRC-nexus, China-linked cyber espionage threat actor tracked by Google Threat Intelligence Group (GTIG), with activity observed since at least 2023. GTIG attributes to UNC6508 a long-running campaign targeting North American academic, medical, and military research organizations, including clinical providers, academic centers, military health institutions, advocacy groups, and health regulatory bodies in the United States and Canada. Reported intelligence interests included defense and national security information, Indo-Pacific operations, artificial intelligence, uncrewed systems, cyber offensive programs, advanced technology, military readiness, geo-strategic policy, and medical research. GTIG reported that UNC6508 regularly targeted externally facing REDCap servers, likely including vulnerable legacy versions, although the exact initial access method was not confirmed. In documented intrusions, the actor deployed a web shell named help.php and later installed custom malware called INFINITERED. INFINITERED was tailored for REDCap environments and consisted of modular persistence, credential-harvesting, and backdoor components. It trojanized legitimate REDCap system files, intercepted REDCap upgrades to reinject malicious code and maintain persistence, harvested usernames and passwords submitted through REDCap login pages, stored stolen credentials in REDCap database tables, and accepted encrypted commands via the REDCAP-TOKEN HTTP cookie. Reported backdoor capabilities included shell command execution, file upload and download, SQL query execution, retrieval and deletion of stolen credentials, and collection of system and database information. UNC6508 used harvested credentials to access internal networks and administrator accounts and, in at least one case, remained undetected for more than a year. GTIG also described a novel exfiltration technique in which UNC6508 abused enterprise content compliance rules after obtaining administrative access. The actor created a rule named "Patroit" that matched targeted keywords and patterns and silently BCC-forwarded matching emails to the actor-controlled Gmail account BebitaBarefoot774@gmail.com. GTIG reported that UNC6508 used strong operational security, including US-based obfuscation network IPs, compromised routers, residential proxies, VPS infrastructure, legitimate credentials, bulk-sourced accounts, and operation-specific infrastructure. Additional reporting cited UNC6508 in broader China-linked targeting of defense-related entities and noted use of operational relay box (ORB) networks. The only alias directly provided in the content is UNC6508.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics39 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078×4
Valid Accounts
T1190×6
Exploit Public-Facing Application
T1195
Supply Chain Compromise
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.004
Unix Shell
T1574
Hijack Execution Flow
TA0003
Persistence
5 techniques
T1078×4
Valid Accounts
T1505
Server Software Component
T1505.003×4
Web Shell
T1546
Event Triggered Execution
T1554
Compromise Host Software Binary
T1556
Modify Authentication Process
TA0004
Privilege Escalation
2 techniques
T1078×4
Valid Accounts
T1546
Event Triggered Execution
TA0005
Stealth
3 techniques
T1027×2
Obfuscated Files or Information
T1078×4
Valid Accounts
T1574
Hijack Execution Flow
TA0112
Defense Impairment
1 technique
T1556
Modify Authentication Process
TA0006
Credential Access
4 techniques
T1056×2
Input Capture
T1056.001
Keylogging
T1056.003
Web Portal Capture
T1555
Credentials from Password Stores
T1556
Modify Authentication Process
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
1 technique
T1083
File and Directory Discovery
TA0009
Collection
3 techniques
T1056×2
Input Capture
T1056.001
Keylogging
T1056.003
Web Portal Capture
T1114×4
Email Collection
T1114.003×3
Email Forwarding Rule
T1213×2
Data from Information Repositories
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001×2
Web Protocols
T1090×2
Proxy
T1090.002
External Proxy
T1090.003×2
Multi-hop Proxy
T1105
Ingress Tool Transfer
TA0010
Exfiltration
2 techniques
T1041×2
Exfiltration Over C2 Channel
T1567×2
Exfiltration Over Web Service
IOCS

Observables

8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

malware newsNews
Jun 15, 2026
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research - Malware News - Malware Analysis, News and Indicators

Espionage campaign targeting North American academic, medical, and military research organizations by compromising externally facing REDCap servers, deploying INFINITERED, harvesting credentials, pivoting into internal systems, and exfiltrating sensitive email data via manipulated content compliance rules.

Read more
security weekNews
Jun 15, 2026
Chinese Hackers Target Medical, Military, and AI Research in North America - SecurityWeek

Cyberespionage campaign targeting major medical, academic, and military research organizations in North America, with additional interest in national security, AI, drones, cyber offensive research, defense technology, naval assets, diplomatic and government entities, and military command units.

Read more
register securityNews
Jun 15, 2026
Google says PRC-linked spies hid in medical research networks for more than a year

PRC-linked espionage group that compromised externally facing REDCap servers at North American medical and military research organizations, deployed the custom InfiniteRed malware, harvested credentials, maintained long-term persistence, accessed internal networks, and exfiltrated sensitive defense, technology, policy, and medical research emails via Google Workspace compliance rules.

Read more
bleeping computerNews
Jun 15, 2026
Chinese hackers breach REDCap servers, steal medical research

China-linked espionage campaign targeting exposed REDCap servers at medical and research organizations in North America, deploying the InfiniteRed malware to steal credentials and sensitive data and using email content compliance rules for exfiltration.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping29

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables8

Domains, IPs, and hashes tied to this actor, refreshed continuously.