Tuesday August 18, 2026

Advisory ID: NCC-CSIRT-2026-031

Summary: 

The NCC-CSIRT has alerted Telecommunications Service Providers to a cyber espionage campaign reportedly linked to a China-associated threat actor, UNC6508, based on information from the OSGF and Google’s Threat Intelligence Group (GTIG). The campaign targeted research institutions by exploiting vulnerabilities in REDCap servers, deploying custom malware, and stealing sensitive data. Although Nigerian telecommunications infrastructure is not currently a direct target, Telecommunications Service Providers are encouraged to stay vigilant and strengthen cybersecurity measures to support the resilience of Nigeria’s digital ecosystem.

Damage: Critical

Probability: Medium

Product(s): 

  • REDCap (Research Electronic Data Capture) Platforms
  • Research Information Management Systems
  • Institutional Email Systems
  • Clinical Research Databases
  • Academic and Healthcare Information Systems

Platform(s): 

  • Windows
  • Linux
  • Web-Based REDCap Deployments
  • Enterprise Email Platforms
  • Research Network Infrastructure

Description: 

According to information received from the Office of the Secretary to the Government of the Federation (OSGF), citing findings reportedly published by Google's Threat Intelligence Group (GTIG), a China-linked threat actor identified as UNC6508 has conducted cyber-espionage operations targeting research organisations in North America.

The campaign reportedly exploited vulnerabilities in REDCap servers to gain unauthorised access to institutional networks. Following compromise, the attackers allegedly deployed a custom malware known as INFINITERED, designed to maintain persistence by surviving software updates and enabling long-term access to compromised systems. The report also indicates that the threat actor manipulated email forwarding mechanisms to collect sensitive communications and exfiltrate valuable research data covertly.

Although the reported campaign does not directly target telecommunications infrastructure, Telecommunications Service Providers support the digital connectivity upon which many critical sectors, including healthcare, higher education, research institutions, and government agencies, depend. Accordingly, Telecommunications Service Providers are encouraged to remain aware of emerging cyber espionage campaigns and continue strengthening cybersecurity monitoring, information sharing, and support for institutional customers that may be affected by similar threats.

Consequences: 

Successful exploitation may result in:

  • Unauthorized access to sensitive information.
  • Theft of intellectual property and research data.
  • Persistent compromise of enterprise networks.
  • Unauthorized monitoring of institutional email communications.
  • Exposure of confidential research and healthcare information.
  • Reputational, operational, and regulatory impacts.

Threat Types: 

  • Advanced Persistent Threat (APT)
  • Cyber Espionage
  • Unauthorized Access
  • Malware Deployment
  • Data Exfiltration
  • Credential Compromise
  • Email Surveillance
  • Intelligence Collection

Solutions/Mitigations:  

Successful influence operations may result in:

  • Disseminate this advisory to relevant cybersecurity and network operations personnel for situational awareness.
  • Continue monitoring global cyber threat intelligence concerning Advanced Persistent Threat (APT) activities.
  • Encourage enterprise customers, particularly research, healthcare, and academic institutions, to implement timely security updates and vulnerability management practices.
  • Support the adoption of Multi-Factor Authentication (MFA), robust access controls, and continuous security monitoring across enterprise environments.
  • Maintain close collaboration with NCC-CSIRT and relevant national authorities regarding significant cybersecurity incidents affecting critical sectors.
  • Promote cybersecurity awareness among institutional customers regarding evolving cyber espionage threats.

References:

Office of the Secretary to the Government of the Federation (OSGF), Nigeria. GOOGLE THREAT GROUP REPORT ALLEGES ESPIONAGE BY CHINA-LINKED HACKERS. Confidential Correspondence dated 14 July 2026.