logo

China-Linked OP-512 Targets IIS Servers With Unique Web Shell Framework

ID: dfb4b93e-e22d-54b9-8aa6-196a3cbf344c

STIX ID: report--dfb4b93e-e22d-54b9-8aa6-196a3cbf344c

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-08

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

ReliaQuest identified a suspected China-linked espionage cluster named OP-512 that sustained intermittent access to an internet-facing, end-of-life IIS/.NET server for at least 75 days and later deployed multiple custom web shells and encrypted command handlers. Each web shell is uniquely built per deployment (randomized variables, junk code, embedded RSA keys) and uses dual notification (hex-encoded DNS subdomains with HTTP fallback) to report back, while command handlers require RSA-signed and RC4-encrypted payloads. The actor timestomps files, forces ASP.NET compilation artifacts to persist, loads post-exploitation toolkits (including “Potato” escalators) reflectively in memory, and employs strong operational security, making detection reliant on behavioral telemetry and targeted mitigations such as isolating hosts, monitoring long hex-segmented DNS from w3wp.exe, and clearing ASP.NET temporary compilation artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.