UNC6508
UNC6508 is a PRC-nexus, China-linked cyber espionage threat actor tracked by Google Threat Intelligence Group (GTIG), with activity observed since at least 2023. GTIG attributes to UNC6508 a long-running campaign targeting North American academic, medical, and military research organizations, including clinical providers, academic centers, military health institutions, advocacy groups, and health regulatory bodies in the United States and Canada. Reported intelligence interests included defense and national security information, Indo-Pacific operations, artificial intelligence, uncrewed systems, cyber offensive programs, advanced technology, military readiness, geo-strategic policy, and medical research. GTIG reported that UNC6508 regularly targeted externally facing REDCap servers, likely including vulnerable legacy versions, although the exact initial access method was not confirmed. In documented intrusions, the actor deployed a web shell named help.php and later installed custom malware called INFINITERED. INFINITERED was tailored for REDCap environments and consisted of modular persistence, credential-harvesting, and backdoor components. It trojanized legitimate REDCap system files, intercepted REDCap upgrades to reinject malicious code and maintain persistence, harvested usernames and passwords submitted through REDCap login pages, stored stolen credentials in REDCap database tables, and accepted encrypted commands via the REDCAP-TOKEN HTTP cookie. Reported backdoor capabilities included shell command execution, file upload and download, SQL query execution, retrieval and deletion of stolen credentials, and collection of system and database information. UNC6508 used harvested credentials to access internal networks and administrator accounts and, in at least one case, remained undetected for more than a year. GTIG also described a novel exfiltration technique in which UNC6508 abused enterprise content compliance rules after obtaining administrative access. The actor created a rule named "Patroit" that matched targeted keywords and patterns and silently BCC-forwarded matching emails to the actor-controlled Gmail account BebitaBarefoot774@gmail.com. GTIG reported that UNC6508 used strong operational security, including US-based obfuscation network IPs, compromised routers, residential proxies, VPS infrastructure, legitimate credentials, bulk-sourced accounts, and operation-specific infrastructure. Additional reporting cited UNC6508 in broader China-linked targeting of defense-related entities and noted use of operational relay box (ORB) networks. The only alias directly provided in the content is UNC6508.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage campaign targeting North American academic, medical, and military research organizations by compromising externally facing REDCap servers, deploying INFINITERED, harvesting credentials, pivoting into internal systems, and exfiltrating sensitive email data via manipulated content compliance rules.
Cyberespionage campaign targeting major medical, academic, and military research organizations in North America, with additional interest in national security, AI, drones, cyber offensive research, defense technology, naval assets, diplomatic and government entities, and military command units.
PRC-linked espionage group that compromised externally facing REDCap servers at North American medical and military research organizations, deployed the custom InfiniteRed malware, harvested credentials, maintained long-term persistence, accessed internal networks, and exfiltrated sensitive defense, technology, policy, and medical research emails via Google Workspace compliance rules.
China-linked espionage campaign targeting exposed REDCap servers at medical and research organizations in North America, deploying the InfiniteRed malware to steal credentials and sensitive data and using email content compliance rules for exfiltration.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.