logo

China-Linked Group Deploys Custom ASPX and ASHX Web Shells

ID: 85dd2f07-af9f-54fd-ab72-fea4f95a1cef

STIX ID: report--85dd2f07-af9f-54fd-ab72-fea4f95a1cef

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: Lucas Martin

...
...

ReliaQuest outlines OP-512, a China-linked espionage cluster using a purpose-built .aspx/.ashx web shell framework against internet-facing IIS servers: the implants use a Base64→RC4→RSA execution pipeline, hex-encoded DNS self-reporting, randomized handlers to evade hashing, and in-memory privilege escalation; the report includes IOCs (domains, IPs, C2 details) and concrete mitigation guidance such as blocking long hex-subdomain DNS from w3wp.exe and removing end-of-life .NET from exposed servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.