Executive Summary
Google Threat Intelligence Group (GTIG) has identified a sophisticated espionage campaign by UNC6508, a PRC-nexus actor targeting North American academic, medical, and military research organizations. The actor remained undetected for over a year by exploiting REDCap servers, a widely used clinical research platform, to deploy custom malware and pivot into internal environments.
Technically, the campaign utilized INFINITERED, a modular PHP-based malware that trojanizes legitimate REDCap system files to intercept software upgrades, harvest user credentials, and establish backdoors via HTTP cookies. A notable shift in tradecraft involved the use of a novel exfiltration technique where the actor created unauthorized 'content compliance rules' in cloud productivity suites to silently forward sensitive emails matching specific strategic keywords to actor-controlled accounts.
This activity represents a high-impact threat to organizations involved in AI, medical breakthroughs, and national defense. The actor's use of obfuscation (OBF) networks and US-based residential proxies complicates attribution and traditional IP-based detection, requiring organizations to focus on behavioral monitoring of administrative tool abuse and application integrity.
