Google Exposes China-Linked Hacking Group UNC6508: Two Years Inside Networks Stealing AI and Defense Research
The hackers didn't attack the firewall — they rewrote the victims' own email rules so the intelligence forwarded itself out.
Three Key Facts
On June 15, Google's Threat Intelligence Group (GTIG) published a report attributing, with high confidence, a cyberespionage group called UNC6508 to China, targeting medical, academic, and military research institutions across North America. The earliest known compromise dates to September 2023, with activity continuing through November 2025 — meaning the group sat undetected inside victim networks for more than two years.
The intrusion worked by compromising the research database platform REDCap and deploying custom malware called INFINITERED. REDCap is a web platform hospitals and universities across North America widely use to build research databases. The malware trojanizes REDCap's own system files and hijacks its upgrade process — every platform update automatically reinjects the backdoor — while harvesting usernames and passwords from the login page and taking commands via HTTP cookies.
The cleverest part is the exfiltration: the attackers rewired the victims' own Google Workspace compliance rules. They created a content compliance rule named "Patroit" that used regular expressions to match keywords, silently BCC-forwarding any matching email to a Gmail account they controlled. The rule's keyword list exposed their interests: geo-strategic policy, military equipment, advanced technology (including AI and uncrewed vehicles), offensive cyber programs, and medical research.
WangDou's Take
The story worth chewing on here isn't "Chinese hackers strike again" — it's how little work it took. Traditional data theft means constantly shipping files out, which traffic monitoring can catch. This group simply edited the compliance rules your own inbox already ships with, and let your own Google system forward the intelligence one email at a time, quiet as an invisible extra recipient on the CC line. Going undetected for two years shows how well the "borrow the enemy's own knife" approach works. And the fact that "artificial intelligence" sits right there on the keyword list tells you that, to state-level intelligence, AI research now ranks alongside military hardware and drones — no longer just commercial competition, but a strategic asset to be seized. Companies spend every day bolting guardrails onto their models, and miss that the backdoor may be hiding in their own email settings.
Source: Google Cloud · The Hacker News · SecurityWeek
