logo

China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS

ID: dba98074-99b2-50db-a4c1-2a054702cdd5

STIX ID: report--dba98074-99b2-50db-a4c1-2a054702cdd5

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: Eswar

...
...

ReliaQuest observed a China-linked cluster tracked as OP-512 compromising an IIS host (Windows Server 2016, .NET 4.0) using a custom, purpose-built web shell framework. The intrusion featured long-term persistence (access established ~75 days earlier), dual command channels via .ashx handlers with RC4+RSA-protected command pipeline, hex-segmented DNS “phone home” signaling with an HTTP Meterpreter fallback, timestomping to hide file metadata, and memory-only privilege escalation tools; the report includes IOCs (domains, IPs, ports) and mitigations for IIS environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.