Activity timeline
UNC6508 appears in 3 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
- T1090.003 Multi-hop Proxy — Command and Controlobserved in 2 of 3 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 2 of 3 tracked threats
- T1505 Server Software Component — Persistenceobserved in 2 of 3 tracked threats
- T1505.003 Web Shell — Persistenceobserved in 2 of 3 tracked threats
- T1555.003 Credentials from Web Browsers — Credential Accessobserved in 2 of 3 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 2 of 3 tracked threats
Tracked threats
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North American Medical, Academic & Military ResearchHIGH