UNC6508: How a Chinese State-Sponsored Group Spent 26 Months Inside US and Canadian Research Labs Using a Misspelled Gmail Rule
Google’s Threat Intelligence Group disclosed a 26-month Chinese state-sponsored espionage campaign against US and Canadian research institutions. UNC6508 exploited legacy REDCap versions to deploy modular malware INFINITERED, escalated to domain administrator, then exfiltrated emails by weaponizing a legitimate Google Workspace content compliance rule — silently BCC’ing matching messages on defense intelligence, AI, unmanned vehicles, and medical research to an attacker-controlled Gmail address. Disrupted by Google in November 2025. No victims named publicly.
