OP-512 is a newly identified espionage-focused threat cluster assessed by ReliaQuest with moderate to high confidence as likely linked to China. The group has been observed targeting Microsoft Internet Information Services (IIS) servers, particularly legacy internet-facing environments such as Windows Server 2016 systems running outdated or end-of-life .NET Framework 4.0, to maintain stealthy, long-term intelligence-gathering access. ReliaQuest describes OP-512 as a previously undocumented and distinct cluster, while noting tactical proximity to other China-linked IIS-focused activity including CL-STA-0048, DragonRank, and GhostRedirector; possible overlap with broader China-linked tradecraft was also noted, including similarities to activity associated with Flax Typhoon. OP-512 is tracked separately and no direct overlap was established. The actor deploys a custom three-part web shell framework on compromised IIS servers. Reported capabilities include remote browser-based access, file management, two authenticated command channels, and centralized reporting of newly deployed web shells. The framework is designed for evasion: each deployment is cryptographically unique, uses cryptographic access controls including RSA signature verification and RC4 encryption, randomizes variable names, adds junk code, and produces different file hashes across deployments. OP-512 also uses timestomping to alter malicious file timestamps so they blend with legitimate files and hinder forensic timeline reconstruction. A notable tradecraft element is a self-reporting mechanism that sends the deployed web shell's location via hex-encoded DNS queries, with HTTP fallback. ReliaQuest noted this DNS technique overlaps with CL-STA-0048, although OP-512's tooling did not otherwise cleanly match that cluster. In the observed intrusion, the actor used the IIS worker process to drop web shells into an upload directory and evidence indicated the same host had been accessed roughly 75 days earlier, suggesting patient, persistent operations. OP-512 also attempted privilege escalation by loading tools directly into IIS process memory without writing them to disk, including multiple components from the Potato Suite; one report also noted an undocumented tool labeled GhostKit in telemetry. Commands such as whoami and whoami /priv were used to verify privileges. Endpoint protection terminated malicious processes, but IIS worker process restarts allowed tooling to reload, and malicious DLLs were later found in the ASP.NET temporary directory. Known alias in the provided content: op_512.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked espionage cluster targeting IIS servers using a custom web shell framework with cryptographically unique deployments, self-reporting web shell location via DNS with HTTP fallback, in-memory privilege escalation tooling, and anti-detection measures such as timestomping and randomized code generation.
A likely China-linked espionage cluster conducting long-term intelligence-gathering via a compromised IIS web server, using a custom web shell framework with cryptographically unique payloads, encrypted access controls, centralized management, persistent access, privilege escalation, and multiple command channels.
A newly identified espionage cluster suspected of having ties to China that targets Internet Information Services (IIS) web servers using a custom, cryptographically unique web shell framework, in-memory privilege escalation tooling, and persistence techniques designed to evade detection and survive process restarts.
Espionage-focused activity cluster targeting Microsoft IIS servers using a custom multi-component web shell framework for remote access and defense evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.