China-linked OP-512 Threat Cluster Targets Microsoft IIS Servers

China-linked OP-512 Threat Cluster Targets Microsoft IIS Servers

First seen 5 Jun 2026, 22:22 UTC Feeds.4SysopsScworldGbhackersCybersecuritynews 88% similarity 72.5

Article Content

Browse articles
ThreatCluster

The OP-512 threat cluster has been identified as actively targeting Microsoft Internet Information Services (IIS) servers, with a focus on espionage. Researchers attribute this activity to China, marking it as the fourth group to exploit IIS vulnerabilities in the past year. OP-512 employs a sophisticated web shell framework consisting of three distinct web shells, designed for remote access while avoiding detection. The group uses techniques like timestomping to manipulate file timestamps and blend in with legitimate files. Targeted systems include legacy IIS servers, such as those running Windows Server 2016 with outdated .NET Frameworks. The attack method involves dropping a web shell via the server's worker process, which reports its location to an attacker-controlled domain. Additionally, OP-512 attempts privilege escalation to the SYSTEM level using the Potato Suite. The advanced tooling suggests a deliberate design to evade defenses against known China-linked groups, creating significant challenges for defenders relying on signature-based detection.

Key Points: • OP-512 targets legacy Microsoft IIS servers, focusing on espionage. • The group uses a custom web shell framework with advanced evasion techniques. • This marks the fourth China-linked group exploiting IIS vulnerabilities in the past year.

ThreatCluster AI

Timeline

2026-06-05
OP-512 threat cluster identified
Researchers report OP-512 targeting Microsoft IIS servers with a custom web shell framework for espionage.
Scworld
2026-06-05
Espionage focus confirmed
The OP-512 group is believed to select targets aligned with Chinese intelligence priorities.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story