SECURITYCYBERSCOOP
Google exposes China espionage group that’s been lurking in networks undetected since 2023
Google threat hunters identified UNC6508, a Chinese state-sponsored espionage group active since 2023, which infiltrated government and private organizations in the U.S. and Canada to steal data from sectors including academia, medicine, and military. The group used a custom backdoor called INFINITERED and exploited REDCap servers, remaining undetected for over a year before being discovered in late 2025.
Mentioned
Related Signal
Adjacent reporting
- China-linked hackers targeted Mongolian government using Slack, Discord for covert communications
- PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data
- Chinese APT deploys new malware to keep access to hacked networks
- What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia
- Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
- China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists