Scworld China-linked OP-512 Threat Cluster Targets Microsoft IIS Servers
Article Content
- •OP-512 targets legacy Microsoft IIS servers, focusing on espionage.
- •The group uses a custom web shell framework with advanced evasion techniques.
- •This marks the fourth China-linked group exploiting IIS vulnerabilities in the past year.
The OP-512 threat cluster has been identified as actively targeting Microsoft Internet Information Services (IIS) servers, with a focus on espionage. Researchers attribute this activity to China, marking it as the fourth group to exploit IIS vulnerabilities in the past year. OP-512 employs a sophisticated web shell framework consisting of three distinct web shells, designed for remote access while avoiding detection. The group uses techniques like timestomping to manipulate file timestamps and blend in with legitimate files. Targeted systems include legacy IIS servers, such as those running Windows Server 2016 with outdated .NET Frameworks. The attack method involves dropping a web shell via the server's worker process, which reports its location to an attacker-controlled domain. Additionally, OP-512 attempts privilege escalation to the SYSTEM level using the Potato Suite. The advanced tooling suggests a deliberate design to evade defenses against known China-linked groups, creating significant challenges for defenders relying on signature-based detection.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…