Threats · 101 days ago
OP-512 matters because it turns IIS hunting into a detection problem, not just an exposure problem. The cluster uses per-deployment web shells that are uniquely generated, restricted to the operator, and designed to confuse both signatures and forensic timelines, so a server can already be compromised even when routine checks look clean.
ReliaQuest says OP-512 is a previously unreported China-linked espionage cluster targeting Microsoft IIS servers. Its three-web-shell framework also backdates its own file timestamps to match the surrounding directory, which makes fresh implants look like long-present files and can throw off timeline-based triage.
The larger risk is that IIS defenses tuned to older China-linked groups may not catch this one if they rely on known shell names or broad signatures. For defenders of internet-facing IIS servers, the problem is not just who is behind it, but that the implant is built to blend into the host it already controls.
1 source covering this story
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
A newly identified China-linked threat cluster, OP-512, is targeting Microsoft IIS servers with a custom three-web-shell framework for espionage.
Part of the PlainSec briefing for 2026-06-05