ReliaQuest disclosed a newly tracked espionage cluster, OP-512, that targeted internet-facing Microsoft IIS servers running outdated software, including a compromised Windows Server 2016 host using unsupported .NET Framework 4.0. Investigators said the actor likely maintained access for roughly 75 days before returning to deploy a custom three-file web shell framework designed to produce cryptographically unique installations, obscure forensic timelines through timestomping, and report its location back to operators through hex-encoded DNS queries with HTTP fallback.
The intrusion relied on layered evasion and persistence, including randomized variable names, junk code, RSA signature verification, RC4 encryption, and malicious DLLs stored in the ASP.NET temporary directory. OP-512 also loaded multiple privilege-escalation tools directly into IIS process memory, including several from the Potato Suite and an undocumented utility dubbed GhostKit; even when endpoint protection terminated malicious processes, IIS worker process restarts allowed the tooling to reload. ReliaQuest assessed the cluster with moderate-high confidence as China-linked and potentially related in tradecraft to other IIS-focused operations, while urging defenders to retire or isolate legacy .NET servers, restrict script execution in upload paths, and remediate the original access vector rather than only removing web shells.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
ReliaQuest Threat Research correlated suspicious events on a customer network into a single incident and identified a previously undocumented espionage cluster named OP-512, assessing it with moderate-high confidence as China-linked and distinct from other known IIS-focused operations.
In the later intrusion phase, the China-linked cluster tracked as OP-512 compromised a Windows Server 2016 IIS host running unsupported .NET Framework 4.0, deployed a custom three-file web shell framework, and loaded multiple privilege-escalation tools including Potato Suite variants and GhostKit into IIS process memory.
ReliaQuest investigators found that the threat actor had accessed the compromised IIS server roughly 75 days before the later tooling deployment, indicating an earlier foothold before the main intrusion activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.