Lead story
UNC6508: China's Quiet Year Inside Medical and Military Research Networks
For more than a year, a Chinese state-linked hacking group sat inside the networks of medical institutions, defence contractors, and AI research facilities across North America — and nobody noticed. Google's Threat Intelligence Group disclosed the campaign Monday, attributing it to a cluster it tracks as UNC6508, which it says has been active since at least early 2025.
The group's method of entry was REDCap — an open-source research data platform widely used by universities and hospitals to manage clinical trial data. Attackers found internet-exposed REDCap servers, exploited them to drop a custom malware family researchers are calling InfiniteRed, and then settled in for the long game. Not ransomware. Not noise. Just quiet, sustained collection.
What they were after tells you a lot about Beijing's priorities right now. According to Google, the stolen material spans medical research data, drone and aerospace technology, pathogen research, and AI development work. That's not a smash-and-grab — it's a shopping list aligned directly with China's strategic technology goals under Made in China 2025 and its successor frameworks.
The dwell time is the part that should keep security teams up at night. Twelve-plus months undetected, siphoning data through Gmail accounts to blend outbound traffic with normal web activity. By the time Google disrupted the campaign, the damage — in terms of intellectual property — was already done.
REDCap is the thread worth pulling here. The platform is deployed at hundreds of universities, hospitals, and research bodies worldwide. It's often managed by research IT teams rather than dedicated security teams, which means patching cadences can be slow and exposure can be invisible to central security operations. Any institution running a public-facing REDCap instance should treat this as a fire drill.
The pattern also mirrors what we've seen from other Chinese espionage clusters — Salt Typhoon's long residency in US telco networks, Volt Typhoon's pre-positioning in critical infrastructure — but with a sharper focus on intellectual property over access and disruption. The target profile suggests UNC6508 is filling gaps in China's domestic R&D pipeline.
Australian institutions are directly in scope here. REDCap is widely deployed across Australian universities and hospital networks — the University of Melbourne, Monash, and several state health departments use it for clinical research. Australian universities collaborate extensively with North American research programmes, often sharing data environments. The ACSC's guidelines on protecting research data are relevant here, as is the Government's existing guidance under the Research Security Action Plan, which specifically flags foreign interference in university research as a priority threat vector.
Watch for: whether Google's disclosure leads to a coordinated advisory from the Five Eyes intelligence alliance, which has previously issued joint alerts on Chinese espionage activity targeting research institutions. An ACSC advisory in the coming days wouldn't be surprising.
