Portsuppe

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Mandiant Blog·3h·Reputable

Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration

Categories cybersecurity · government-security · unknown-it-category-15
Original source / advisory
Published
6/15/2026, 2:00:00 PM
Fetched
6/15/2026, 3:19:29 PM
Trust
reputable · 80/100
Language
en