← Back to feed
Threat Actors & CampaignsEmerging1 sourceJun 15, 2026 · 14:00via Mandiant / Google TI

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Brief

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair

Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community.

While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration.

The threat actor had broad collection aspirations, including sensitive defense intelligence related to national security, Indo-Pacific command operations, artificial intelligence, uncrewed vehicle systems, cyber offensive programs, and medical research.

GTIG disrupted the malicious infrastructure associated with this threat actor.

Read more on Mandiant / Google TI