THREAT INTELLIGENCE REPORT

UNC6508 Abuse of Google Workspace Compliance Rules for Email Exfiltration

Analysis of a China-Linked Cyber Espionage Campaign Targeting Research, Healthcare and Defense Organizations

Analyst
Rajkumar G
Date
16 June 2026
Classification
Public
Report Type
Threat Intelligence

Executive Summary

A China-linked cyber espionage actor tracked as UNC6508 conducted a long-term intelligence collection campaign against healthcare, academic, research, and defense-related organizations in North America. The campaign leveraged compromised REDCap servers and custom malware known as INFINITERED to maintain persistence and harvest credentials. Following privilege escalation, the threat actor abused Google Workspace Content Compliance Rules to silently copy sensitive emails to attacker-controlled accounts. This activity demonstrates the increasing use of legitimate cloud administration features for covert data exfiltration and highlights the need for organizations to monitor cloud administrative actions in addition to traditional endpoint and network activity.

Key Intelligence Overview

Threat Actor

UNC6508

Severity

High

Motivation

Espionage

Malware

INFINITERED

Targets

Research & Defense

Confidence

High

Threat Actor Attribution

Google Threat Intelligence Group attributed this activity with high confidence to UNC6508, a China-linked espionage cluster focused on intelligence gathering operations. The threat actor demonstrated interest in collecting information related to military strategy, defense technology, artificial intelligence, offensive cyber operations, healthcare research, and geopolitical policy. The operation appears consistent with long-term strategic intelligence collection objectives rather than financial motivations.

Targeted Sectors

Campaign Timeline

September 2023

Earliest observed compromise activity.

Late 2023

Deployment of INFINITERED malware on REDCap servers.

2024

Credential harvesting and internal reconnaissance.

2024–2025

Privilege escalation and lateral movement activities.

November 2025

Email exfiltration via Google Workspace compliance rules.

Attack Chain Analysis

Initial Access

UNC6508 compromised internet-facing REDCap servers. Public reporting indicates the actor targeted older and potentially vulnerable REDCap deployments.

Persistence

The actor deployed INFINITERED malware which modified REDCap system files and survived software upgrades by reinjecting malicious code during future update cycles.

Credential Access

INFINITERED harvested usernames and passwords entered through REDCap authentication portals and stored collected credentials in encrypted form.

Privilege Escalation

Using harvested credentials and internal reconnaissance, the actor obtained elevated privileges including domain administrator access.

Collection

The threat actor targeted communications and documents related to strategic policy, defense programs, artificial intelligence, healthcare research, and advanced technologies.

Exfiltration

Rather than deploying dedicated exfiltration malware, UNC6508 created Google Workspace Content Compliance Rules which automatically copied matching emails to attacker-controlled accounts.

MITRE ATT&CK Mapping

Tactic Observed Technique
Initial Access Exploit Public-Facing Application
Persistence Server-Side Component
Credential Access Credentials from Web Forms
Discovery Account Discovery
Privilege Escalation Valid Accounts
Collection Email Collection
Exfiltration Exfiltration to Cloud Services

Indicators of Interest

Threat Actor

Malware

Suspicious Artifacts

Detection Opportunities

Defensive Recommendations

  1. Patch externally exposed REDCap servers.
  2. Remove unsupported or legacy REDCap deployments.
  3. Implement phishing-resistant MFA.
  4. Review and audit Google Workspace compliance rules.
  5. Monitor cloud administrative activities.
  6. Conduct periodic threat hunting exercises.
  7. Review privileged account access regularly.

Confidence Assessment

Confidence Level: High The technical findings, attribution assessment, and campaign details are based on reporting from Google Threat Intelligence Group and supporting industry analysis.

Analyst Assessment

This campaign highlights a growing trend in which adversaries abuse trusted cloud-native administrative features rather than deploying traditional malware for data exfiltration. The use of Google Workspace Content Compliance Rules enabled the threat actor to blend malicious actions with legitimate administrative activity, reducing visibility and complicating detection efforts. Organizations should expand monitoring capabilities beyond endpoint telemetry and network traffic to include cloud audit logs, configuration changes, and administrative activity within SaaS platforms.

Intelligence Sources

References