150 Secret Passwords Opened the Doors... Espionage Campaign Inside American Programs

A hacking group linked to China spent more than a year stealing sensitive data from academic, medical, and military research institutions in the United States and Canada before its activities were discovered, Google announced.
In a report, Google Threat Intelligence Group stated that between September 2023 and November 2025, the hackers sought information related to defense intelligence, military strategy in the Indo-Pacific region, artificial intelligence, unmanned vehicles, cyber warfare programs, and medical research.
The campaign was attributed to a hacking group known as UNC6508, a relatively new cyber espionage entity about which little information is available.
Luke McNamara, Senior Analyst at Google Threat Intelligence Group, said the group’s methods closely align with China-linked hacking activities observed over the years, focusing on collecting information likely of interest to the Chinese government.
The earliest known activity linked to the campaign dates back to September 2023, when hackers exploited vulnerabilities in servers running REDCap, an electronic application widely used by nonprofit institutions to create, manage, and administer online surveys and databases.
Subsequently, they set up a system that automatically redirected emails containing any of approximately 150 keywords and search terms to a Gmail account under their control, according to researchers.