As cited
Copy frozen at (site build).
threat intel
ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512
ReliaQuest's AI platform identified OP-512, a previously undocumented China-linked threat cluster targeting legacy Internet Information Services (IIS) servers through a custom web shell framework with cryptographic protections that evade signature-based detection. OP-512 represents at least the fourth China-linked cluster publicly documented targeting IIS servers in the past year, with a focus on espionage and long-term access maintenance. Organizations running end-of-life .NET frameworks on internet-facing servers face elevated risk and should prioritize migration or network segmentation.
Why it matters: Organizations operating internet-facing IIS servers with legacy .NET frameworks require immediate assessment and remediation planning, as OP-512 and similar clusters are actively targeting this infrastructure for state-sponsored espionage with tools designed to bypass existing defenses.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512
ReliaQuest's automated threat intelligence system identified a new China-linked espionage cluster designated OP-512, which deployed custom cryptographically unique web shells to a compromised Internet Information Services (IIS) server. The cluster represents at least the fourth China-linked group targeting legacy IIS servers in the past year and exhibits operational signatures distinct from known actors. Organizations operating end-of-life .NET frameworks on internet-facing infrastructure face immediate risk and should prioritize migration or network segmentation.
Why it matters: Security teams managing IIS servers, especially those running legacy .NET frameworks, need to assess their exposure to this cluster and similar China-linked operations targeting DMZ infrastructure; espionage actors maintain access for extended periods before exfiltrating data, making rapid detection and segmentation critical.
- Source published
- First seen by Cybersecurity Tracker