Google Exposes UNC6508: Chinese-Linked Hackers Spent Two Years Inside US and Canadian Research Networks

Google's Threat Intelligence Group has named UNC6508, a Chinese-linked hacking group that spent over two years inside US and Canadian defence, AI, and medical research networks via REDCap exploits. The campaign's scope and dwell time carry direct lessons for GCC research and government institutions.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
Security professional in a corporate server room reviewing threat intelligence data following disclosure of Chinese-linked UNC6508 cyberespionage campaign

Security professional in a corporate server room reviewing threat intelligence data following disclosure of Chinese-linked UNC6508 cyberespionage campaign

Google's Threat Intelligence Group has publicly attributed a sustained cyberespionage campaign to a Chinese-linked hacking group it designates UNC6508, revealing that the group operated undetected inside US and Canadian academic, medical, and military research institutions for more than two years, from September 2023 to November 2025.

The disclosure, published on 15 June 2026, represents one of the more significant nation-state threat intelligence releases of the year. The targeted organisations collectively employ thousands of researchers and hold combined budgets running into the billions of dollars. Their work spanned drug discovery, clinical trials, public health policy, defence intelligence, military strategy in the Indo-Pacific, artificial intelligence development, unmanned vehicle programmes, and cyber warfare research. Google declined to name the institutions directly, citing ongoing investigations and the sensitivity of the affected parties.

The entry point for UNC6508 was REDCap, a web application widely used by academic and nonprofit institutions to build and manage secure online surveys and research databases. The group exploited vulnerabilities in REDCap servers to steal legitimate login credentials, then used those credentials to establish persistent access to targeted networks without triggering standard authentication alerts. Once inside, the attackers configured an automated email forwarding system targeting nearly 150 pre-defined keywords and search terms, routing any matching correspondence to a Gmail account under their control.

The keyword list encompassed phone numbers and email addresses of individuals at targeted organisations, as well as terms covering geo-strategic policy, advanced military technology, Indo-Pacific strategy, AI research priorities, and medical research directions. The approach is consistent with a long-running pattern of Chinese-linked espionage that prioritises intelligence collection over disruption: gain quiet persistent access, automate data harvest, and maintain dwell time for as long as detection avoidance allows.

Luke McNamara, Deputy Chief Analyst at Google Threat Intelligence Group, described UNC6508 as a relatively new and previously little-known cyberespionage cluster. He noted that its methods are broadly consistent with Chinese-linked hacking activity observed across many years, focused on gathering information of interest to the Chinese government. Beijing, as is standard practice, denied involvement through its embassy in Washington.

The campaign's 26-month dwell time is operationally significant. Most enterprise environments are calibrated to detect anomalous behaviour in the near term. An adversary operating inside trusted infrastructure using legitimate credentials, forwarding emails through a commercial webmail provider, and targeting research data rather than financial systems or operational technology will generate minimal noise in conventional SIEM or EDR tooling. The group was ultimately detected, but the investigation does not establish a precise trigger.

For GCC enterprise and government security teams, the UNC6508 disclosure carries several practical implications.

  • First, REDCap is used across research institutions, government-affiliated academic bodies, and healthcare organisations in the Gulf. Security teams should immediately audit whether REDCap instances are patched against the vulnerabilities exploited in this campaign and whether credential hygiene across these systems meets current standards.
  • Second, automated email forwarding rules set by compromised administrator accounts are a detection opportunity that many organisations do not actively monitor. Audit rules and forwarding configurations on collaboration and email platforms should be a standard component of periodic security reviews.
  • Third, and more broadly, the campaign illustrates why application-layer vulnerabilities in trusted research and productivity platforms remain a preferred initial access vector for nation-state actors. The attacker does not need to breach a perimeter directly if a web application used by thousands of institutions globally has an exploitable flaw and slow patch adoption.

GCC research institutions, Saudi Arabia's Vision 2030-aligned technology programmes, and government-affiliated AI initiatives in the UAE operate in an environment where the same categories of data that UNC6508 targeted, defence research, AI development, and public health intelligence, are being actively developed and scaled. The threat intelligence community has documented Chinese-linked espionage interest in Gulf technology programmes before. UNC6508 is a reminder that the methodology is systematic, patient, and difficult to detect without targeted hunting rather than passive monitoring.

Google notified all identified compromised organisations before publishing the report. Organisations running REDCap or similar research data management platforms should treat this disclosure as a prompt for immediate patch review, credential audit, and email forwarding rule inspection, regardless of whether they have observed anomalous activity. As GCC enterprise security platforms continue to evolve, the capacity to detect lateral movement using legitimate credentials remains one of the most important and frequently undertested capabilities in the regional security stack.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Nation State Threat Intelligence GCCChinese Cyberespionage CampaignsLong Dwell Intrusion DetectionApplication Layer ExploitationMENA Threat Intelligence 2026Enterprise Credential Security GulfResearch Institution Cyber Risk