logo

OP-512: China-Linked Hackers Hit IIS Servers With New Tool

ID: ea98f6cf-fcbf-5ed4-9017-ddc16fa74f5f

STIX ID: report--ea98f6cf-fcbf-5ed4-9017-ddc16fa74f5f

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Do Son

...
...

**OP-512:** ReliaQuest identified a previously undocumented China-linked espionage cluster that deployed cryptographically unique IIS web shells on Internet-facing, legacy .NET servers; the threat used DNS-based self-reporting (with HTTP fallback), RC4 encryption, RSA signatures, timestomping, reflective .NET assembly loading and in-memory privilege escalation tools to persist and evade signature-based detection, and defenders are advised to prioritize migration/segmentation and behavioral detection for unusual DNS patterns and reflective loading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.