news.mlab.sh
Back to the feed
threat-intel

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

High
Summary

A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity to China-aligned espionage, highlighting a recurring pattern of targeting legacy IIS servers with similar groups. This cluster’s unique framework and proactive evasion measures pose a significant challenge for traditional security defenses.

The threat cluster, dubbed OP-512, has been identified as actively targeting Microsoft Internet Information Services (IIS) servers, deploying a bespoke web shell framework. This framework consists of three web shells designed to grant attackers remote access while employing techniques like timestomping to evade detection and complicate forensic investigations. The operation involved scanning files, manipulating timestamps, and utilizing cryptographic controls for access restriction and centralized management. The initial activity, involving DNS queries to ashx.lhlsjcb[.]com, occurred approximately 75 days prior to the deployment of the web shells, which were then dropped onto the server using the w3wp.exe worker process.

ReliaQuest has assessed a strong link between OP-512 and China-aligned espionage activities, mirroring tactics observed in other groups like CL-STA-0048, DragonRank, and GhostRedirector. The group’s autonomous operation and unique framework distinguish it from these previously identified clusters. Following web shell deployment, the attacker attempted privilege escalation using the Potato Suite and confirmed their elevated rights with commands like "whoami /priv". The targeting of legacy IIS servers running Windows Server 2016 with .NET Framework 4.0, coupled with the cluster’s proactive evasion strategies, underscores the ongoing vulnerability of internet-facing systems.

This activity highlights the continued risk posed by China-linked actors targeting government and defense sectors across Southeast Asia and the broader trend of exploiting outdated software. The sophistication of OP-512, particularly its purpose-built framework, suggests a deliberate effort to bypass existing detection methods, demanding a shift in defensive strategies for organizations relying on traditional threat intelligence.

Read the full article at The Hacker News