Minacce · 116 giorni fa
OP-512 è importante perché trasforma il hunting su IIS in un problema di detection, non solo di exposure. Il cluster usa web shell per singola deployment, generate in modo univoco, limitate all'operator e progettate per confondere sia le signatures sia le timeline forensi, così che un server possa essere già compromesso anche quando i controlli di routine risultano puliti.
1 fonte che coprono questa storia
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
A newly identified China-linked threat cluster, OP-512, is targeting Microsoft IIS servers with a custom three-web-shell framework for espionage.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-05