Threats · 101 days ago

Custom IIS Web Shells Slip Past Old Hunting Rules

OP-512 matters because it turns IIS hunting into a detection problem, not just an exposure problem. The cluster uses per-deployment web shells that are uniquely generated, restricted to the operator, and designed to confuse both signatures and forensic timelines, so a server can already be compromised even when routine checks look clean.

ReliaQuest says OP-512 is a previously unreported China-linked espionage cluster targeting Microsoft IIS servers. Its three-web-shell framework also backdates its own file timestamps to match the surrounding directory, which makes fresh implants look like long-present files and can throw off timeline-based triage.

The larger risk is that IIS defenses tuned to older China-linked groups may not catch this one if they rely on known shell names or broad signatures. For defenders of internet-facing IIS servers, the problem is not just who is behind it, but that the implant is built to blend into the host it already controls.

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-06-05

Editions

Related stories