OP-512: China-Linked Hackers Hit IIS Servers With New Tool
ID: ea98f6cf-fcbf-5ed4-9017-ddc16fa74f5f
STIX ID: report--ea98f6cf-fcbf-5ed4-9017-ddc16fa74f5f
Feed Name: securityonline.info
**OP-512:** ReliaQuest identified a previously undocumented China-linked espionage cluster that deployed cryptographically unique IIS web shells on Internet-facing, legacy .NET servers; the threat used DNS-based self-reporting (with HTTP fallback), RC4 encryption, RSA signatures, timestomping, reflective .NET assembly loading and in-memory privilege escalation tools to persist and evade signature-based detection, and defenders are advised to prioritize migration/segmentation and behavioral detection for unusual DNS patterns and reflective loading.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
