Custom IIS Web Shells Slip Past Old Hunting Rules

OP-512 matters because it turns IIS hunting into a detection problem, not just an exposure problem. The cluster uses per-deployment web shells that are uniquely generated, restricted to the operator, and designed to confuse both signatures and forensic timelines, so a server can already be compromised even when routine checks look clean. ReliaQuest says OP-512 is a previously unreported China-linked espionage cluster targeting Microsoft IIS servers. Its three-web-shell framework also backdates its own file timestamps to match the surrounding directory, which makes fresh implants look like long-present files and can throw off timeline-based triage. The larger risk is that IIS defenses tuned to older China-linked groups may not catch this one if they rely on known shell names or broad signatures. For defenders of internet-facing IIS servers, the problem is not just who is behind it, but that the implant is built to blend into the host it already controls.

Part of the PlainSec briefing for 2026-06-05

Sources