www.darkreading.com 6/15/2026, 4:50:49 PM · external

China-Nexus Actor Spied on US Researchers Undetected for a Year

China-Nexus Actor Spied on US Researchers Undetected for a Year
Developing story campaign 2 articles tracked
Chinese cyberespionage campaign targets US medical, military and AI research
CyberSIXT Evidence Panel
Primary Source cloud.google.com
Threat Actor
UNC6508

A China-aligned threat actor, UNC6508, conducted an extensive spying campaign on US academic, medical, and military institutions for over a year, utilizing custom malware to steal credentials from researchers' Web applications. Discovered by Google Threat Intelligence Group, this operation targeted sensitive data from multiple high-profile organizations and showcased innovative data exfiltration techniques, making detection challenging.

Google collaborated with Mandiant to disrupt the activity and alerts other potential targets. Recommendations for organizations include enforcing two-factor authentication and monitoring for unauthorized changes.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline