Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Cyber Threat OP-512 Hits Microsoft IIS Servers

New Cyber Threat OP-512 Hits Microsoft IIS Servers

Posted on June 5, 2026 By CWS

Cybersecurity researchers have identified a novel threat cluster named OP-512, specifically targeting Microsoft Internet Information Services (IIS) servers. This group employs a customized web shell framework to compromise these servers, signaling a significant cybersecurity concern.

Origins and Connections to China

ReliaQuest has expressed moderate to high confidence that OP-512’s activities are espionage-driven and linked to China. Although OP-512 does not overlap with known China-aligned adversaries, it is the fourth group, following CL-STA-0048, DragonRank, and GhostRedirector, to target IIS servers within the past year. Previously, Cisco Talos noted Chinese-speaking cybercriminals sharing the BadIIS malware variant to target these servers.

Web Shell Framework and Evasion Techniques

The core of OP-512’s operations involves a sophisticated web shell framework that provides remote access and employs techniques to evade detection. By manipulating timestamps through a method called timestomping, the attackers obscure the activity timeline of their web shells, complicating forensic investigations.

This framework showcases rare capabilities, such as unique deployments restricted to attackers via cryptographic controls, and a mechanism for compromised servers to report back for centralized management. These features suggest OP-512’s operations are distinct and autonomous, possibly indicating a revamped toolset or independent development.

Attack Execution and Implications

In a documented attack, OP-512 targeted a legacy IIS server running outdated Windows Server 2016 software. Evidence pointed to prior malicious activity 75 days before the main incident, involving DNS queries to an attacker-controlled domain.

The attackers executed a rapid sequence of actions, deploying a web shell via the server’s worker process and triggering a reporting mechanism. This allowed them to manage files, execute commands, and report the compromise efficiently. Attempts to escalate privileges using the Potato Suite were also noted.

ReliaQuest highlighted the concerning trend of four China-linked clusters targeting similar technology within a year, emphasizing the ongoing risk to organizations using outdated IIS servers. OP-512’s unique approach, utilizing a bespoke framework, presents a challenge to traditional detection methods.

Organizations are urged to reassess their security defenses, as OP-512 employs advanced tactics that bypass conventional threat detection strategies. Vigilant monitoring and updates to security protocols are essential to mitigate the risk posed by such sophisticated cyber threats.

The Hacker News Tags:China, cyber threat, Cybersecurity, Espionage, IIS servers, Malware, OP-512, ReliaQuest, threat intelligence, web shell

Post navigation

Previous Post: Chinese Hackers Exploit BRICKSTORM to Infiltrate Networks
Next Post: Chrome 149 Update Fixes Record 429 Security Flaws

Related Posts

China-Linked Hackers Exploit New VMware Zero-Day Since October 2024 China-Linked Hackers Exploit New VMware Zero-Day Since October 2024 The Hacker News
ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks The Hacker News
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices The Hacker News
Adapting Security Strategies for Near-Zero Exploit Windows Adapting Security Strategies for Near-Zero Exploit Windows The Hacker News
OpenClaw Flaws Risk Data Security and System Control OpenClaw Flaws Risk Data Security and System Control The Hacker News
An Anti-Sales Guide for MSPs An Anti-Sales Guide for MSPs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark