New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
swapupdate.in Jun 6, 2026

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

AI-summarised brief · reviewed before publication

Cybersecurity researchers have discovered a threat cluster called OP-512, which targets Microsoft Internet Information Services servers to deploy a custom web shell framework. The activity is linked to China with moderate to high confidence. OP-512 is the fourth China-linked threat group to target IIS servers in the past 12 months. The group uses a custom web shell framework to grant remote access to compromised hosts while evading detection. The framework consists of three web shells and uses techniques like timestomping to manipulate timestamps. OP-512 is a distinct cluster operating autonomously, with close tactical proximity to another group called CL-STA-0048, and has been found to target legacy IIS servers.

💡 Why It Matters

  • · OP-512's ability to develop and deploy custom web shell frameworks underscores China's growing sophistication in cyber espionage.
  • · Its focus on IIS servers highlights a vulnerability that could be exploited by other threat actors.