A cyber-espionage campaign targeting university research networks has been uncovered, with attackers seeking unpublished work in quantum computing, biotechnology and advanced materials.

The intruders used credentials phished from visiting researchers and exploited unpatched library-access portals to move into research data stores. Activity was traced across at least 14 institutions in multiple countries.

Analysts attribute the campaign to a state-aligned group known for intellectual property theft, citing tooling overlaps and infrastructure reuse with previous operations against industrial targets.

Universities are being urged to segment research networks, enforce multi-factor authentication and monitor for anomalous access to pre-publication repositories.