Scworld
China-linked OP-512 Threat Cluster Targets Microsoft IIS Servers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The OP-512 threat cluster has been identified as actively targeting Microsoft Internet Information Services (IIS) servers, with a focus on espionage. Researchers attribute this activity to China, marking it as the fourth group to exploit IIS vulnerabilities in the past year. OP-512 employs a sophisticated web shell framework consisting of three distinct web shells, designed for remote access while avoiding detection. The group uses techniques like timestomping to manipulate file timestamps and blend in with legitimate files. Targeted systems include legacy IIS servers, such as those running Windows Server 2016 with outdated .NET Frameworks. The attack method involves dropping a web shell via the server's worker process, which reports its location to an attacker-controlled domain. Additionally, OP-512 attempts privilege escalation to the SYSTEM level using the Potato Suite. The advanced tooling suggests a deliberate design to evade defenses against known China-linked groups, creating significant challenges for defenders relying on signature-based detection.
Key Points: • OP-512 targets legacy Microsoft IIS servers, focusing on espionage. • The group uses a custom web shell framework with advanced evasion techniques. • This marks the fourth China-linked group exploiting IIS vulnerabilities in the past year.