New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
AI-summarised brief · reviewed before publication
Cybersecurity researchers have discovered a threat cluster called OP-512, which targets Microsoft Internet Information Services servers to deploy a custom web shell framework. The activity is linked to China with moderate to high confidence. OP-512 is the fourth China-linked threat group to target IIS servers in the past 12 months. The group uses a custom web shell framework to grant remote access to compromised hosts while evading detection. The framework consists of three web shells and uses techniques like timestomping to manipulate timestamps. OP-512 is a distinct cluster operating autonomously, with close tactical proximity to another group called CL-STA-0048, and has been found to target legacy IIS servers.
💡 Why It Matters
- · OP-512's ability to develop and deploy custom web shell frameworks underscores China's growing sophistication in cyber espionage.
- · Its focus on IIS servers highlights a vulnerability that could be exploited by other threat actors.