Google reveals China-linked group UNC6508 stole US-Canada medical research data after over two years of infiltration

On June 15, Google’s Threat Intelligence Group (GTIG) released a report disclosing that a China-linked threat actor, UNC6508, has been active since at least September 2023 through November 2025. Over the course of more than two years, the actor silently infiltrated medical, academic, and military research institutions in the United States and Canada, remaining undetected within victim networks for over a year. The attackers exploited REDCap, a clinical data management platform widely used by research institutions (possibly targeting vulnerable older versions), to deploy custom malware called InfiniteRed to steal legitimate credentials and used novel techniques to exfiltrate data stealthily. GTIG Senior Security Engineer Patrick Whitsell noted that the targets of the theft were “extremely broad,” encompassing medical research, U.S. defense strategies, and advanced technology fields such as autonomous drones and unmanned vehicles — a departure from typical directed espionage operations that focus on a single objective.

The targeted institutions include prominent clinical medical centers, top academic institutions, military medical units in North America, professional advocacy groups, and health regulatory agencies — collectively employing thousands of people and holding research budgets totaling billions of dollars. Stolen targets include national security intelligence, Indo-Pacific theater strategy, artificial intelligence, unmanned systems, cyber attack and defense projects, and medical research (including research related to the Chikungunya virus). Google said it did not explicitly attribute the operation to the Chinese government but said evidence points to the People’s Republic of China. GTIG, along with its subsidiary Mandiant Consulting, has dismantled the group’s malicious infrastructure, notified affected institutions one by one, and shared relevant threat intelligence on the Google Security Operations (SecOps) platform to help defenders identify indicators of compromise.

The Wall Street Journal | Google Cloud Blog | Reuters | https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research