New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
ID: e5d9328b-d01b-5bd2-99d6-e23c2a8d290e
STIX ID: report--e5d9328b-d01b-5bd2-99d6-e23c2a8d290e
Feed Name: The Hacker News
OP-512 is an espionage-oriented threat cluster attributed with moderate-to-high confidence to China that targets Internet-facing Microsoft IIS servers to deploy a bespoke three-part web shell framework providing file management, authenticated command execution via two access paths, and automated compromise reporting; operators use timestomping to blend artifacts with surrounding files, drop shells via the IIS worker process (w3wp.exe), beacon via DNS/HTTP to attacker domains, and attempt SYSTEM escalation using the Potato suite against legacy Windows Server 2016 hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
