discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

Researchers found OP-512, a likely China-linked espionage cluster, targeting Microsoft IIS servers with a custom web shell framework and stealth tricks.

By Ravie Lakshmanan·Jun 5·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
Image: thehackernews.com

ReliaQuest says OP-512 is a new threat cluster focused on compromised Microsoft IIS servers. Its bespoke framework uses three web shells, timestomping, and automated reporting to keep access hidden and manageable at scale.

Why it matters

This adds another IIS-focused China-linked cluster to a pattern that defenders are already seeing across the last year. It matters because the tooling appears purpose-built to evade the detection methods that work against known actors.

Researchers found a sneaky hacker group hiding in web servers like a thief using a fake back door. The group tries to look like it has always been there and even changes the clock on its tools to avoid being noticed.

Analysis

What ReliaQuest found

ReliaQuest says it discovered a previously unreported threat cluster it tracks as OP-512, with moderate to high confidence that the activity is linked to China. The group appears to focus on espionage and was observed compromising Microsoft IIS servers to deploy a custom web shell framework.

How the framework works

The core of the intrusion is a set of three web shells that give the attacker remote access while reducing the chances of detection. ReliaQuest says the tooling is designed to avoid signature-based defenses and to blur forensic timelines. One technique described in the report is timestomping: the attacker scans nearby files and folders, calculates a median last-modified time, and then rewrites the web shells’ timestamps to blend in.

The company also says the framework is unusually controlled. Each deployment is uniquely generated, attacker access is restricted through cryptographic controls, and compromised servers automatically report back for centralized management. In the observed case, the attacker used a legacy IIS server on Windows Server 2016 with end-of-life .NET Framework 4.0.

Attack sequence and implications

ReliaQuest says there was evidence of earlier activity on the same host roughly 75 days before the main incident, including DNS queries to another attacker-controlled domain. During the later incident, the attacker used w3wp.exe to place a web shell in an upload directory, which then triggered a self-reporting step using DNS or HTTP as a fallback channel.

After the web shells were in place, the attacker tried to escalate privileges to SYSTEM using the Potato Suite and checked rights with commands such as whoami /priv.

ReliaQuest argues that OP-512 is distinct from other China-aligned IIS-focused clusters, even though it shares tactical proximity with CL-STA-0048. The main defender takeaway is that legacy, internet-facing IIS servers remain a favored entry point, and this cluster’s custom tooling may not be covered by defenses tuned only for known actors.

Key points

  • OP-512 is a newly identified threat cluster that ReliaQuest says is likely linked to China.
  • The group targets Microsoft IIS servers and uses a custom three-shell framework for remote access.
  • Its tooling uses timestomping and automated reporting to hide artifacts and manage compromises at scale.
  • The observed intrusion targeted a legacy Windows Server 2016 IIS host with end-of-life .NET Framework 4.0.
  • ReliaQuest says the framework appears distinct from other known China-aligned IIS-focused groups.
The Upside

If defenders catch this pattern early, they can focus on legacy IIS systems, unusual DNS callbacks, and timestamp tampering as hunting clues. Better visibility into these tactics could help organizations spot similar intrusions before the attacker reaches higher privileges.

The Downside

The bigger risk is that the group’s custom framework may slip past defenses built for known malware and known actors. If organizations keep exposing unsupported IIS and old .NET installations, the same kind of espionage access may continue to succeed.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritychinaresearchtech

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 5, 2026

Source

thehackernews.com

Share

Topics

securitychinaresearchtech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…