New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
Researchers found OP-512, a likely China-linked espionage cluster, targeting Microsoft IIS servers with a custom web shell framework and stealth tricks.
Intelligence analysis by GPT-5.4 Mini

ReliaQuest says OP-512 is a new threat cluster focused on compromised Microsoft IIS servers. Its bespoke framework uses three web shells, timestomping, and automated reporting to keep access hidden and manageable at scale.
Researchers found a sneaky hacker group hiding in web servers like a thief using a fake back door. The group tries to look like it has always been there and even changes the clock on its tools to avoid being noticed.
Analysis
What ReliaQuest found
ReliaQuest says it discovered a previously unreported threat cluster it tracks as OP-512, with moderate to high confidence that the activity is linked to China. The group appears to focus on espionage and was observed compromising Microsoft IIS servers to deploy a custom web shell framework.
How the framework works
The core of the intrusion is a set of three web shells that give the attacker remote access while reducing the chances of detection. ReliaQuest says the tooling is designed to avoid signature-based defenses and to blur forensic timelines. One technique described in the report is timestomping: the attacker scans nearby files and folders, calculates a median last-modified time, and then rewrites the web shells’ timestamps to blend in.
The company also says the framework is unusually controlled. Each deployment is uniquely generated, attacker access is restricted through cryptographic controls, and compromised servers automatically report back for centralized management. In the observed case, the attacker used a legacy IIS server on Windows Server 2016 with end-of-life .NET Framework 4.0.
Attack sequence and implications
ReliaQuest says there was evidence of earlier activity on the same host roughly 75 days before the main incident, including DNS queries to another attacker-controlled domain. During the later incident, the attacker used w3wp.exe to place a web shell in an upload directory, which then triggered a self-reporting step using DNS or HTTP as a fallback channel.
After the web shells were in place, the attacker tried to escalate privileges to SYSTEM using the Potato Suite and checked rights with commands such as whoami /priv.
ReliaQuest argues that OP-512 is distinct from other China-aligned IIS-focused clusters, even though it shares tactical proximity with CL-STA-0048. The main defender takeaway is that legacy, internet-facing IIS servers remain a favored entry point, and this cluster’s custom tooling may not be covered by defenses tuned only for known actors.
Key points
- OP-512 is a newly identified threat cluster that ReliaQuest says is likely linked to China.
- The group targets Microsoft IIS servers and uses a custom three-shell framework for remote access.
- Its tooling uses timestomping and automated reporting to hide artifacts and manage compromises at scale.
- The observed intrusion targeted a legacy Windows Server 2016 IIS host with end-of-life .NET Framework 4.0.
- ReliaQuest says the framework appears distinct from other known China-aligned IIS-focused groups.
If defenders catch this pattern early, they can focus on legacy IIS systems, unusual DNS callbacks, and timestamp tampering as hunting clues. Better visibility into these tactics could help organizations spot similar intrusions before the attacker reaches higher privileges.
The bigger risk is that the group’s custom framework may slip past defenses built for known malware and known actors. If organizations keep exposing unsupported IIS and old .NET installations, the same kind of espionage access may continue to succeed.



