By Elias Schisgall
A China-linked cyberattacker managed to infiltrate the servers of major North American medical research institutions, including some run by militaries, while remaining undetected for more than one year, Google cybersecurity researchers said.
A Monday report from the Google Threat Intelligence Group said an attacker called "UNC6508," described as "a People's Republic of China-nexus threat actor," deployed malware to exfiltrate data from servers belonging to leading clinical providers, academic research centers, regulatory bodies and North American military health institutions.
The attackers sought to collect data around medical research, geo-strategic policy, military strategy and advanced technology research including artificial-intelligence. They also sought information around Chikungunya, a mosquito-transmitted viral disease which had an outbreak in China beginning last year.
"This ambitious scope of intelligence collection from UNC6508 may suggest a broader range of targets beyond the identified victims in the medical research community," the Google researchers said. "GTIG assesses these collection priorities are aligned with the strategic interests of the People's Republic of China."
Beginning in September 2023, the attackers used malware to capture login credentials for Research Electronic Data Capture, or REDCap, servers commonly used by medical researchers. The design of REDCap servers allowed the attackers to target legacy versions of software on the systems, researchers said.
"This highlights not only the increasing importance of rapidly applying security patches, but also promptly removing older software versions to prevent downgrade attacks," the researchers said.
The researchers didn't say whether AI tools were used in the attack. But the news comes as cybersecurity researchers and firms have been sounding the alarm around the potential for AI to accelerate cyberattacks.
A coalition of companies had been using Anthropic's Mythos AI model to patch software vulnerabilities under the moniker Project Glasswing, in a race to bolster cybersecurity measures faster than increasingly capable AI models can break them.
The Trump administration last week banned companies and individuals from using Mythos 5 or Fable 5 - a version of Mythos released to the public - over reports that the models contained vulnerabilities which could aid cyberattackers, according to The Wall Street Journal.
Write to Elias Schisgall at elias.schisgall@wsj.com
(END) Dow Jones Newswires
06-15-26 1345ET



















