China-Nexus Espionage Group UNC6508 Targeted North American Medical Research Networks in Multiyear Cyber Campaign
核心洞察
Google Threat Intelligence Group (搜索) identified UNC6508, a PRC-nexus threat group, conducting multiyear cyber espionage against U.S. and Canadian medical research institutions since at least September 2023.
Attackers exploited vulnerable REDCap (搜索) servers to deploy custom malware called InfiniteRed, stealing legitimate credentials and maintaining persistent access for over a year.
The campaign targeted medical research including Chikungunya (搜索) virus studies, correlating with a July 2025 outbreak in China's Guangdong province, alongside defense and AI information.
A China-nexus threat group conducted a sustained, multiyear espionage campaign targeting medical research institutions across the United States and Canada, deploying custom malware to steal sensitive clinical data and credentials, according to a report released Monday by Google Threat Intelligence Group (搜索) (GTIG).
The threat cluster, tracked as UNC6508, compromised vulnerable Research Electronic Data Capture (REDCap (搜索)) servers at multiple North American organizations, including "world-renowned clinical providers, premier academic centers, North American military health institutions, professional advocacy groups, and health regulatory bodies," the report stated.
"We know UNC6508 was attempting to gather information on a broad scope of objectives, including medical research, U.S. defense strategy and advanced technology, such as autonomous defense and uncrewed vehicle systems," said Patrick Whitsell, senior security engineer at GTIG.
Chikungunya (搜索) Research Among Specific Targets
Among the medical research targeted was work related to Chikungunya (搜索), a mosquito-borne viral disease. GTIG researchers noted that these specific searches correlated with a July 2025 outbreak of the virus in China's Guangdong province, suggesting a direct link between the espionage activity and pressing public health concerns within China.
Luke McNamara, deputy chief analyst at GTIG, described the collection priorities as unusually broad: "It's one of the most interesting grocery shopping lists of things to collect that I've seen from a state-sponsored actor." While defense-related activity constituted a significant portion of the search terms, the intruders also sought out specific medical research facilities and the Chikungunya (搜索) pathogen.
Infection Chain and Custom Malware
Researchers traced the hacking campaign back to September 2023, when a REDCap (搜索) server at a North American medical research center was first compromised. Although GTIG could not determine the initial access vector, they noted that REDCap had issued critical security fixes for remote code execution vulnerabilities in 2023.
After three months of潜伏, the attackers deployed custom malware dubbed InfiniteRed, designed with three modular components: persistent remote access through code injection during REDCap (搜索) upgrade processes, a credential harvester injected into the authentication system, and a backdoor executing on every REDCap page load.
The stolen credentials were subsequently used to access administrator accounts and penetrate victims' internal networks. The compromise at the earliest known victim continued undetected until November 2025 — a span of more than two years.
Data Exfiltration via Content Compliance Rules
UNC6508 employed a particularly stealthy exfiltration method, creating a content compliance rule named "Patroit" (a misspelling of "Patriot") within cloud-based enterprise productivity suites. This legitimate feature was abused to silently BCC-forward emails matching predefined keywords and address patterns to an attacker-controlled Gmail account, BebitaBarefoot774@gmail.com.
The forwarded communications delivered "a steady stream of geo-strategic policy, military strategy, advanced technology, and medical research emails" to the PRC-linked operatives. GTIG has since disabled the Gmail account to prevent further data exfiltration.
Broader Implications for Healthcare Cybersecurity
Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center, warned that the campaign raises larger security concerns for healthcare organizations. "Even when the apparent motive is espionage, the same access paths can be repurposed later for disruption or extortion, which in healthcare can quickly become a patient-safety issue if critical systems are impacted," Weiss said.
McNamara noted that Google's incident responders have notified all identified victims and offered support, adding, "we suspect there's probably even more." The researchers also raised questions about why medical research institutions were being searched for defense-related terms such as unmanned drones and vehicles, theorizing that the threat group may have been "copy-and-pasting this across multiple victims" or that targeted institutions maintained research connections with military or government agencies.
