Threat Intelligence
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
Cyber RTJune 5, 20263 min read

Cybersecurity researchers have identified a new threat cluster, OP-512, targeting Microsoft IIS servers with a custom web shell framework. This group is distinct from other known adversaries, using unique, sophisticated tools to evade detection. OP-512 exploits legacy IIS servers, escalating privileges and reporting back to attacker domains, highlighting ongoing risks to outdated systems.
Cybersecurity researchers have identified a new threat cluster named OP-512, which targets Microsoft Internet Information Services (IIS) servers to deploy a custom web shell framework. This activity is believed to be linked to Chinese espionage efforts, as per the findings by ReliaQuest. The targeted servers align with sectors and regions of interest to Chinese intelligence priorities, suggesting a strategic focus on gathering sensitive information through compromised web infrastructure.
OP-512 is the fourth threat group in the past year to target IIS servers, following others like CL-STA-0048, DragonRank, and GhostRedirector. This trend highlights a growing interest among China-aligned cyber adversaries in exploiting IIS servers. Cisco Talos has also reported that multiple Chinese-speaking cybercrime groups are utilizing a malware variant called BadIIS to compromise these servers, indicating a broader pattern of attacks on this technology.
The operations of OP-512 are centered around a sophisticated web shell framework that includes three web shells. These tools provide attackers with remote access to the compromised servers while employing advanced techniques to avoid detection. One such method is timestomping, which involves altering the timestamps of the web shell artifacts to make them appear as if they have been in place for an extended period, thus complicating forensic investigations.
The framework used by OP-512 is notable for its unique deployment, cryptographic access controls, and centralized management capabilities. Each deployment is custom-generated, and compromised servers report back to the attackers, allowing for efficient management of the compromised infrastructure. This level of sophistication is rarely seen in combination, making OP-512 a significant threat.
There is a tactical resemblance between OP-512 and another group, CL-STA-0048, suggesting that OP-512 might be a revamped version of an existing cluster or an independently developed entity. Despite its origins, OP-512 operates autonomously, indicating a distinct and organized threat actor. The group has been observed targeting legacy IIS servers, specifically those running outdated software like Windows Server 2016 and .NET Framework 4.0, which are vulnerable to exploitation.
The attack sequence involved using the web server's worker process to deploy a web shell in the application's upload directory, triggering a self-reporting mechanism. This mechanism uses DNS queries or HTTP requests to communicate the web shell's location to an attacker-controlled domain. The deployment of the web shells allowed the attackers to manage files, execute commands, and report the compromise before any defensive response could be mounted.
Following the deployment of web shells, OP-512 attempted to escalate privileges to the SYSTEM level using known tools like the Potato Suite. This was followed by executing commands to verify their system rights, demonstrating a methodical approach to gaining control over the compromised server. The repeated targeting of IIS servers by China-linked clusters suggests a coordinated effort to exploit this technology, which remains vulnerable due to its widespread use and legacy software.
ReliaQuest emphasizes that OP-512's use of a bespoke framework differentiates it from other known threat clusters. Unlike groups that rely on commodity tools, OP-512 employs a purpose-built framework designed to evade existing detection methods. This poses a significant challenge for organizations that have tailored their defenses against known actors, as they may not be adequately protected against this new and sophisticated threat.


