{"rewrite":{"id":"r_c9dfcbcc2eed0ecdcb62181a","clusterId":"c_fadbe74899e53289e318976c","slug":"google-reports-chinese-linked-hackers-targeted-medical-research-for-over-a-year","model":"deepseek-v4-flash","headline":"Google Reports Chinese-Linked Hackers Targeted Medical Research for Over a Year","summary":"The Google Threat Intelligence Group reported on June 16, 2026, that a Chinese-linked hacker group, identified as UNC6508, infiltrated medical research institutions in the US and Canada for over a year without detection. The group exploited REDCap server vulnerabilities, deployed custom malware INFINITERED, and exfiltrated data using cloud-based compliance rules.","whyItMatters":"The sustained, undetected campaign against medical and military research facilities highlights a sophisticated state-linked threat targeting sensitive scientific and defense data.","webCardHtml":"\u003cp\u003eThe Google Threat Intelligence Group (GTIG) identified the hacker group as UNC6508 and said the first confirmed breach occurred in September 2023. The group exploited a vulnerability in REDCap, a web application for managing medical research surveys and databases. Three months later, they deployed custom malware called INFINITERED, which stole legitimate login credentials and remained hidden for over a year.\u003c/p\u003e\u003cp\u003eAfter gaining domain administrator privileges, INFINITERED created a content compliance rule named \u0026#39;Patriot\u0026#39; that scanned for keywords including \u0026#39;Indo-Pacific,\u0026#39; \u0026#39;Southeast Asia,\u0026#39; \u0026#39;Commands unit,\u0026#39; and \u0026#39;Artificial Intelligence (AI).\u0026#39; The rule sent matching data to a Gmail account controlled by the hackers. GTIG reported that the group operated until November 2025 and that its infrastructure has since been dismantled.\u003c/p\u003e","blueskyPost":"UNC6508 used REDCap server vulnerabilities and cloud compliance rules to exfiltrate data, showing attackers adapting to evade detection by blending into normal network traffic.","twitterPost":"UNC6508 exploited REDCap server flaws to deploy INFINITERED and exfiltrated data via cloud compliance rules, evading detection for over a year.","threadsPost":"Google's report on UNC6508 reveals a shift in tactics: the group infiltrated medical research institutions by exploiting REDCap server vulnerabilities and used cloud-based compliance rules to exfiltrate data, making their activity blend into normal traffic for over a year.","newsletterBlurb":"The Google Threat Intelligence Group reported that a Chinese-linked hacker group, UNC6508, infiltrated medical research institutions in the US and Canada for over a year without detection. The group exploited REDCap servers, deployed custom malware INFINITERED, and exfiltrated data using cloud-based compliance rules targeting keywords like 'Indo-Pacific' and 'AI.' GTIG said the infrastructure has been dismantled.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260616-chinese-linked-hackers-targeted-medical-research/\",\"title\":\"Google reports that a Chinese-linked hacker group targeted medical research institutions and conducted information gathering activities without being detected\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4158,"outputTokens":579,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1781593085,"createdAt":"2026-06-16T06:47:32.000Z","publishedAt":"2026-06-16T06:49:57.000Z","updatedAt":"2026-06-16T06:49:57.000Z"},"cluster":{"id":"c_fadbe74899e53289e318976c","canonicalTitle":"中国関連のハッカー集団が医学研究機関を標的にして気付かれないまま情報収集活動を行っていたとGoogleが報告","representativeArticleId":"a_1d24c87a24992ccd28cea0ed","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-06-16T06:00:00.000Z","lastSeenAt":"2026-06-16T06:00:00.000Z","updatedAt":"2026-06-16T06:49:57.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260616-chinese-linked-hackers-targeted-medical-research/","title":"中国関連のハッカー集団が医学研究機関を標的にして気付かれないまま情報収集活動を行っていたとGoogleが報告"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["The first confirmed breach occurred in September 2023, when the group exploited a vulnerability in REDCap, a web application for managing medical research surveys and databases.","Three months after the initial breach, the hackers deployed custom malware called INFINITERED, which stole legitimate login credentials and remained hidden for over a year.","The group operated until November 2025, and its infrastructure has since been dismantled, according to GTIG."]}
