Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6508

Also known as: tracked as, coordinat, INFINITERED, premier academic, JokerDPR

Description

UNC6508—also known as Premier Academic or JokerDPR—is a highly skilled threat actor that specializes in penetrating research institutions across North America. Their preferred vector is the open‑source data collection platform REDCap; by exploiting vulnerable legacy versions they inject custom hooks into update packages, and deploy INFINITERED to tamper with legitimate files and establish persistence. INFINITERED functions as a trojanized loader that captures login credentials from authentication flows, stores them in the REDCap session database, and uses a specially crafted HTTP cookie (REDCAP‑TOKEN) to deliver encrypted payloads. The malware then recursively drops additional components and can pivot into internal networks after credential theft. Once internal access is secured, UNC6508 manipulates content compliance rules and configures email forwarding to transmit stolen data to attacker‑controlled Gmail addresses, thereby covertly exfiltrating sensitive research information. The operation demonstrates sophisticated operational security measures—encrypted payloads, obfuscated binaries, and web‑shell usage—that align with state‑level capabilities. While the exact chronology of attacks remains partially unknown, the group has been active at least since late 2023, targeting healthcare, scientific, defense, aerospace, and energy sectors. Their activity is attributed to China by multiple intelligence units, including GTIG, based on infrastructure overlaps and distinctive targeting patterns.

Goals & Targeting

Targeted Sectors

Healthcare
Education
Defense
Government
Aerospace
Manufacturing
Financial services
Energy
Telecommunications
Nuclear
Chemical
Maritime
Information technology
Legal services
Media
Transportation
Entertainment
Utilities

Targeted Countries / Regions

United States of America
Canada
CN
US
UA
RU
IL
IR
CA
KP
FR
KR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 22 hours ago

Executive Summary

UNC6508 is a PRC‑nexus espionage actor that targets U.S. and Canadian academic, medical, defense, and research institutions by exploiting legacy REDCap servers. The group deploys custom malware (INFINITERED) to harvest credentials, establish persistent access via recursive droppers and backdoor hooks, and exfiltrate data through manipulation of domain compliance rules and email forwarding. The actor employs advanced operational security, making detection difficult while maintaining a high level of sophistication in their exploitation techniques.

Goals & Targeting

UNC6508’s strategic objective is state‑level espionage aimed at obtaining proprietary research, clinical trial data, and defense technology from North American institutions. By compromising REDCap environments they gain privileged access to sensitive datasets and internal credentials, enabling long‑term persistence and lateral movement into national security laboratories and healthcare entities that generate high-value intelligence. The actor focuses on research‑intensive sectors—medical, aerospace, defense, energy—and leverages the ubiquitous use of REDCap among universities and hospitals to widen its foothold across multiple disciplines and countries (U.S., Canada, Israel, Iran, Ukraine, Russia). The campaign reflects a deliberate effort to harvest intellectual property while minimizing exposure through sophisticated exfiltration and operational concealment techniques.

Enhanced Description

Key Capabilities

  • Exploits legacy REDCap versions via public‑facing vulnerabilities
  • Deploys custom malware INFINITERED that trojanizes legitimate REDCap files
  • Harvests user credentials during authentication and stores them in session databases
  • Implements persistent remote access using recursive droppers and backdoor hooks
  • Uses web shells (help.php) for post‑infection management
  • Manipulates domain content compliance rules and email forwarding to exfiltrate data
  • Employs opsec techniques such as obfuscated binaries, multi‑hop proxies, and encrypted payloads via REDCAP‑TOKEN cookies

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Defense Evasion
Exfiltration

ATT&CK Techniques

T1078
T1081
T1105
T1190
T1218.011
T1689
T1071
T1098.007
T1555
T1567
T1055
T1505.003
T1056.003
T1114.003
T1554
T1090.003
T1027
T1213
T1071.001
T1562.001

Software / Tooling

INFINITERED
REDCap
BRICKSTORM
GuLoader
VERMIN
Phishing Kits
Spear‑phishing
PowerShell
Matrix
Dark
CraxsRAT
Hydra
Nexus
Hive
Remote Management Software
Google Drive
WhatsApp
Telegram
Spectr
MESHAGENT
RoundCube
HANGMAN.V2
Web Shell
Trojan
UNC1549
YARA

Campaigns & Victims

Since late 2023, UNC6508 has conducted a focused campaign against U.S. and Canadian research institutions that rely on REDCap for clinical trial data collection. Their methodology—vulnerability exploitation, custom malware deployment, secure credential harvesting, and covert exfiltration via domain rule manipulation—has enabled rapid compromise of high‑value targets across defense, healthcare, and scientific research sectors. The group operates with a steady tempo, often establishing persistence before expanding lateral reach using stolen credentials. Notable operations include the 2023 infiltration of multiple North American universities’ REDCap instances and the 2024 exfiltration of sensitive defense R&D materials to attacker‑controlled Gmail addresses.

IOC Patterns

  • Credential hijacking via POST capture stored in REDCap session database
  • Trojanization of legitimate application files for persistence
  • Encrypted credentials embedded within application database tables
  • Use of HTTP Cookie REDCAP‑TOKEN to transport or trigger encrypted payloads
  • Decryption of payloads using system‑default encryption routine
  • Manipulation of email forwarding rules to exfiltrate data

Recommended Actions

  • Patch and upgrade all legacy REDCap installations promptly to eliminate known vulnerabilities.
  • Disable or remove unsupported REDCap versions that are susceptible to downgrade attacks.
  • Implement multi‑factor authentication and enforce strong password policies to reduce credential harvest risks.
  • Deploy Web Application Firewalls (WAFs) and intrusion detection systems to detect exploitation of publicly‑facing applications.
  • Establish strict change management and file integrity monitoring for REDCap update packages to detect unauthorized hook insertions.
  • Configure web servers and WAFs to flag suspicious HTTP cookies, especially those with unexpected prefixes or containing encoded data.
  • Review email system configuration to block or investigate unauthorized forwarding rules, particularly to external domains such as Gmail.
  • Conduct regular penetration testing focused on credential extraction from cookie parameters in medical research platforms.
  • Educate administrators on opsec best practices for handling third‑party plugins and update routines.

Suggested Tags

UNCK6508
REDCap exploitation
Credential harvesting
Custom malware (INFINITERED)
Persistent remote access
Data exfiltration via domain compliance manipulation
OpSec concealment
PRC nexus
Medical Research
Defense
Healthcare

Confidence Assessment

The attribution of UNC6508 to a China‑aligned actor is supported by multiple intelligence entities and consistent infrastructure overlap, giving high confidence for the core narrative. However, gaps remain regarding the full spectrum of internal lateral movement techniques beyond credential theft, the exact timing of each compromise event, and detailed evidence linking the group to every reported operation beyond tool signatures. Further forensic analysis of compromised systems and expanded IOC coverage would improve confidence in the actor’s tactics, techniques, and procedures, as well as clarify their long‑term strategic objectives.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 7 Filename 1 Email Address 1 IPv4 Address 1 SHA-256 Hash 7

References

  1. cloud.google.com — Cited by web research for: coordinat
  2. cloud.google.com — Cited by web research for: INFINITERED
  3. trial.medpath.com — Cited by web research for: premier academic
  4. www.cybersecuritydive.com — Cited by web research for: Dairy
  5. www.securitymagazine.com — Cited by web research for: Guard
  6. www.securityweek.com — Cited by web research for: Utilities
  7. https://malpedia.caad.fkie.fraunhofer.de/actor/unc6508 — Cited by AI analysis.

Intel Summary

20

Techniques

48

Tools

0

Campaigns

17

IOCs

0

Observed Data

9

Tactics

Tags

APT
Healthcare Targeting
Critical Infrastructure
Phishing
Backdoor / C2
Data Exfiltration
Government Targeting
Espionage
StOLEN Tools (Spear-phishing)
North America
Healthcare Sector
Defence Sector
UNCK6508
REDCap exploitation
Credential harvesting
Custom malware (INFINITERED)
Persistent remote access
Data exfiltration via domain compliance manipulation
OpSec concealment
PRC nexus
Medical Research
Defense
Healthcare

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.