Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Cyber Threat OP-512 Hits Microsoft IIS Servers

New Cyber Threat OP-512 Hits Microsoft IIS Servers

Posted on June 5, 2026 By CWS

Cybersecurity researchers have identified a novel threat cluster named OP-512, specifically targeting Microsoft Internet Information Services (IIS) servers. This group employs a customized web shell framework to compromise these servers, signaling a significant cybersecurity concern.

Origins and Connections to China

ReliaQuest has expressed moderate to high confidence that OP-512’s activities are espionage-driven and linked to China. Although OP-512 does not overlap with known China-aligned adversaries, it is the fourth group, following CL-STA-0048, DragonRank, and GhostRedirector, to target IIS servers within the past year. Previously, Cisco Talos noted Chinese-speaking cybercriminals sharing the BadIIS malware variant to target these servers.

Web Shell Framework and Evasion Techniques

The core of OP-512’s operations involves a sophisticated web shell framework that provides remote access and employs techniques to evade detection. By manipulating timestamps through a method called timestomping, the attackers obscure the activity timeline of their web shells, complicating forensic investigations.

This framework showcases rare capabilities, such as unique deployments restricted to attackers via cryptographic controls, and a mechanism for compromised servers to report back for centralized management. These features suggest OP-512’s operations are distinct and autonomous, possibly indicating a revamped toolset or independent development.

Attack Execution and Implications

In a documented attack, OP-512 targeted a legacy IIS server running outdated Windows Server 2016 software. Evidence pointed to prior malicious activity 75 days before the main incident, involving DNS queries to an attacker-controlled domain.

The attackers executed a rapid sequence of actions, deploying a web shell via the server’s worker process and triggering a reporting mechanism. This allowed them to manage files, execute commands, and report the compromise efficiently. Attempts to escalate privileges using the Potato Suite were also noted.

ReliaQuest highlighted the concerning trend of four China-linked clusters targeting similar technology within a year, emphasizing the ongoing risk to organizations using outdated IIS servers. OP-512’s unique approach, utilizing a bespoke framework, presents a challenge to traditional detection methods.

Organizations are urged to reassess their security defenses, as OP-512 employs advanced tactics that bypass conventional threat detection strategies. Vigilant monitoring and updates to security protocols are essential to mitigate the risk posed by such sophisticated cyber threats.

The Hacker News Tags:China, cyber threat, Cybersecurity, Espionage, IIS servers, Malware, OP-512, ReliaQuest, threat intelligence, web shell

Post navigation

Previous Post: Chinese Hackers Exploit BRICKSTORM to Infiltrate Networks
Next Post: Chrome 149 Update Fixes Record 429 Security Flaws

Related Posts

Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign The Hacker News
Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Devices Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Devices The Hacker News
Webinar on Securing AI Agents Against Cyber Threats Webinar on Securing AI Agents Against Cyber Threats The Hacker News
Critical Windows Flaw Allows SYSTEM Privilege Escalation Critical Windows Flaw Allows SYSTEM Privilege Escalation The Hacker News
MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted The Hacker News
Canadian Arrested for Operating Kimwolf DDoS Botnet Canadian Arrested for Operating Kimwolf DDoS Botnet The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws
  • New Cyber Threat OP-512 Hits Microsoft IIS Servers
  • Chinese Hackers Exploit BRICKSTORM to Infiltrate Networks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws
  • New Cyber Threat OP-512 Hits Microsoft IIS Servers
  • Chinese Hackers Exploit BRICKSTORM to Infiltrate Networks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark