UNC6508 is a People’s Republic of China-nexus cyberespionage threat cluster attributed with high confidence to a long-running campaign against academic, medical, military, public-health, advocacy, regulatory, and defense-related research organizations in the United States and Canada. Known activity spans at least September 2023 through November 2025. Its collection priorities include defense intelligence, geopolitical and Indo-Pacific military strategy, artificial intelligence, uncrewed systems, offensive cyber programs, medical research, clinical trials, and public-health matters. UNC6508 compromises internet-facing REDCap deployments, particularly by probing legacy installations; the precise initial-access method has not been confirmed. Following access, the actor conducts internal reconnaissance and discovers database and service-account credentials, deploys web shells, and uses the bespoke INFINITERED malware family. INFINITERED trojanizes legitimate REDCap components, persists by intercepting and reinfecting software upgrades, harvests credentials submitted to REDCap login portals, and provides backdoor capabilities including command execution, database querying, file transfer, and system-information collection. The actor uses harvested credentials to access internal systems and privileged administrator accounts. It has abused Google Workspace content-compliance rules to covertly BCC emails matching intelligence-related keyword and contact patterns to attacker-controlled accounts, enabling low-noise collection of targeted communications. UNC6508 also employs compromised routers, residential proxies, and other obfuscation infrastructure to conceal operational activity and complicate attribution. The cluster has no confirmed public aliases or identified sub-groups beyond UNC6508.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage targeting academic, medical, and military research organizations in North America.
Suspected compromise of cloud environments to deploy locally hosted open-weight LLM infrastructure, likely to evade provider monitoring.
China-linked espionage cluster targeting academic, medical, and military organizations in North America via REDCap.
Compromised REDCap servers for credential theft and covert email exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.