As cited
Copy frozen at (site build).
threat intel
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
Google's Threat Intelligence Group identified UNC6508, a China-nexus threat actor, conducting a year-long campaign targeting North American medical institutions, academic centers, and military research organizations. The attacker exploited externally facing REDCap servers, deployed custom malware called INFINITERED to harvest credentials, and used those credentials to access internal networks while employing sophisticated operational security techniques to avoid detection. The campaign sought sensitive data on artificial intelligence, defense research, uncrewed systems, cyber operations, and medical research.
Why it matters: Medical institutions, academic research centers, and military health organizations need to audit systems for compromise since initial intrusions occurred as early as September 2023 and went undetected for over a year; security teams should immediately enable phishing-resistant two-factor authentication on administrative accounts and review audit logs for indicators of compromise provided by Google.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
Google's Threat Intelligence Group identified UNC6508, a China-nexus threat actor, conducting a year-long campaign targeting North American medical institutions, academic centers, and military research organizations. The attacker exploited externally facing REDCap servers, deployed custom malware called INFINITERED to harvest credentials, and used those credentials to access internal networks while employing sophisticated operational security techniques to avoid detection. The campaign sought sensitive data on artificial intelligence, defense research, uncrewed systems, cyber operations, and medical research.
Why it matters: Medical institutions, academic research centers, and military health organizations need to audit systems for compromise since initial intrusions occurred as early as September 2023 and went undetected for over a year; security teams should immediately enable phishing-resistant two-factor authentication on administrative accounts and review audit logs for indicators of compromise provided by Google.
- Source published
- First seen by Cybersecurity Tracker