•A China-nexus threat actor, UNC6508, conducted a year-long intelligence gathering campaign against US academic, medical, and military research institutions.
•The attackers leveraged custom malware to steal credentials from a widely used web application and employed a novel technique for stealthy data exfiltration.
•This campaign highlights critical vulnerabilities in web application security, the challenge of detecting sophisticated APTs, and the importance of advanced threat intelligence.
•A China-nexus threat actor, UNC6508, conducted a year-long intelligence gathering campaign against US academic, medical, and military research institutions.
•The attackers leveraged custom malware to steal credentials from a widely used web application and employed a novel technique for stealthy data exfiltration.
•This campaign highlights critical vulnerabilities in web application security, the challenge of detecting sophisticated APTs, and the importance of advanced threat intelligence.