Also known as: tracked as, coordinat, INFINITERED, premier academic, JokerDPR
UNC6508—also known as Premier Academic or JokerDPR—is a highly skilled threat actor that specializes in penetrating research institutions across North America. Their preferred vector is the open‑source data collection platform REDCap; by exploiting vulnerable legacy versions they inject custom hooks into update packages, and deploy INFINITERED to tamper with legitimate files and establish persistence. INFINITERED functions as a trojanized loader that captures login credentials from authentication flows, stores them in the REDCap session database, and uses a specially crafted HTTP cookie (REDCAP‑TOKEN) to deliver encrypted payloads. The malware then recursively drops additional components and can pivot into internal networks after credential theft. Once internal access is secured, UNC6508 manipulates content compliance rules and configures email forwarding to transmit stolen data to attacker‑controlled Gmail addresses, thereby covertly exfiltrating sensitive research information. The operation demonstrates sophisticated operational security measures—encrypted payloads, obfuscated binaries, and web‑shell usage—that align with state‑level capabilities. While the exact chronology of attacks remains partially unknown, the group has been active at least since late 2023, targeting healthcare, scientific, defense, aerospace, and energy sectors. Their activity is attributed to China by multiple intelligence units, including GTIG, based on infrastructure overlaps and distinctive targeting patterns.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6508 is a PRC‑nexus espionage actor that targets U.S. and Canadian academic, medical, defense, and research institutions by exploiting legacy REDCap servers. The group deploys custom malware (INFINITERED) to harvest credentials, establish persistent access via recursive droppers and backdoor hooks, and exfiltrate data through manipulation of domain compliance rules and email forwarding. The actor employs advanced operational security, making detection difficult while maintaining a high level of sophistication in their exploitation techniques.
Goals & Targeting
UNC6508’s strategic objective is state‑level espionage aimed at obtaining proprietary research, clinical trial data, and defense technology from North American institutions. By compromising REDCap environments they gain privileged access to sensitive datasets and internal credentials, enabling long‑term persistence and lateral movement into national security laboratories and healthcare entities that generate high-value intelligence. The actor focuses on research‑intensive sectors—medical, aerospace, defense, energy—and leverages the ubiquitous use of REDCap among universities and hospitals to widen its foothold across multiple disciplines and countries (U.S., Canada, Israel, Iran, Ukraine, Russia). The campaign reflects a deliberate effort to harvest intellectual property while minimizing exposure through sophisticated exfiltration and operational concealment techniques.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since late 2023, UNC6508 has conducted a focused campaign against U.S. and Canadian research institutions that rely on REDCap for clinical trial data collection. Their methodology—vulnerability exploitation, custom malware deployment, secure credential harvesting, and covert exfiltration via domain rule manipulation—has enabled rapid compromise of high‑value targets across defense, healthcare, and scientific research sectors. The group operates with a steady tempo, often establishing persistence before expanding lateral reach using stolen credentials. Notable operations include the 2023 infiltration of multiple North American universities’ REDCap instances and the 2024 exfiltration of sensitive defense R&D materials to attacker‑controlled Gmail addresses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The attribution of UNC6508 to a China‑aligned actor is supported by multiple intelligence entities and consistent infrastructure overlap, giving high confidence for the core narrative. However, gaps remain regarding the full spectrum of internal lateral movement techniques beyond credential theft, the exact timing of each compromise event, and detailed evidence linking the group to every reported operation beyond tool signatures. Further forensic analysis of compromised systems and expanded IOC coverage would improve confidence in the actor’s tactics, techniques, and procedures, as well as clarify their long‑term strategic objectives.
No campaigns linked yet.
No observed data linked yet.
20
Techniques
48
Tools
0
Campaigns
17
IOCs
0
Observed Data
9
Tactics