UNC6508 INFINITERED Campaign Targeting North American Medical Research
Score: 10/10

UNC6508 INFINITERED Campaign Targeting North American Medical Research

UNC6508, a PRC-nexus threat actor, targets medical and military research institutions using INFINITERED malware to harvest credentials and exfiltrate data via manipulated compliance rules.

Executive Summary

Google Threat Intelligence Group (GTIG) has identified a sophisticated espionage campaign by UNC6508, a PRC-nexus actor targeting North American academic, medical, and military research organizations. The actor remained undetected for over a year by exploiting REDCap servers, a widely used clinical research platform, to deploy custom malware and pivot into internal environments.

Technically, the campaign utilized INFINITERED, a modular PHP-based malware that trojanizes legitimate REDCap system files to intercept software upgrades, harvest user credentials, and establish backdoors via HTTP cookies. A notable shift in tradecraft involved the use of a novel exfiltration technique where the actor created unauthorized 'content compliance rules' in cloud productivity suites to silently forward sensitive emails matching specific strategic keywords to actor-controlled accounts.

This activity represents a high-impact threat to organizations involved in AI, medical breakthroughs, and national defense. The actor's use of obfuscation (OBF) networks and US-based residential proxies complicates attribution and traditional IP-based detection, requiring organizations to focus on behavioral monitoring of administrative tool abuse and application integrity.

Key Details

Threat Name

UNC6508 INFINITERED Campaign

Affects

—

Adversary

UNC6508

Malware/Tools

INFINITERED, help.php

Report Score

10out of 10
Quality Score
Excellent
IOC Quality9
TTP Details10
Detection Guidance10
Enterprise Relevance10
Clarity & Structure10
Technical Depth10

Sources