Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-06

UNC6508

As of 2026-08-28, UNC6508 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, campaign, apt. ATT&CK coverage spans 94 techniques across 16 tactics in 3 of 3 tracked threats. Most-observed techniques: T1071.001 (Web Protocols), T1082 (System Information Discovery), T1105 (Ingress Tool Transfer).

Tracked threats
32 high · 1 medium
First seen
2026-06-20
Last seen
2026-07-27
ATT&CK techniques
94across 3 of 3 threats
Related CVEs
5Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 3 tracked threat(s) · Categories: THREAT_INTEL, CAMPAIGN, APT

Activity timeline

UNC6508 appears in 3 tracked threats between and ; the busiest month was 2026-07 with 2 reports.

ATT&CK techniques observed

94 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (17), Resource Development (10), Collection (9), Command and Control (8), Execution (8), Initial Access (8)
  • T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
  • T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
  • T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
  • T1090.003 Multi-hop Proxy — Command and Controlobserved in 2 of 3 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 2 of 3 tracked threats
  • T1505 Server Software Component — Persistenceobserved in 2 of 3 tracked threats
  • T1505.003 Web Shell — Persistenceobserved in 2 of 3 tracked threats
  • T1555.003 Credentials from Web Browsers — Credential Accessobserved in 2 of 3 tracked threats
  • T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 2 of 3 tracked threats

Tracked threats

Related CVEs

5 CVEs referenced by tracked UNC6508 activity