CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2115

As cited

Copy frozen at (site build).

threat intel

ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512

ReliaQuest's AI platform identified OP-512, a previously undocumented China-linked threat cluster targeting legacy Internet Information Services (IIS) servers through a custom web shell framework with cryptographic protections that evade signature-based detection. OP-512 represents at least the fourth China-linked cluster publicly documented targeting IIS servers in the past year, with a focus on espionage and long-term access maintenance. Organizations running end-of-life .NET frameworks on internet-facing servers face elevated risk and should prioritize migration or network segmentation.

Why it matters: Organizations operating internet-facing IIS servers with legacy .NET frameworks require immediate assessment and remediation planning, as OP-512 and similar clusters are actively targeting this infrastructure for state-sponsored espionage with tools designed to bypass existing defenses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512

ReliaQuest's automated threat intelligence system identified a new China-linked espionage cluster designated OP-512, which deployed custom cryptographically unique web shells to a compromised Internet Information Services (IIS) server. The cluster represents at least the fourth China-linked group targeting legacy IIS servers in the past year and exhibits operational signatures distinct from known actors. Organizations operating end-of-life .NET frameworks on internet-facing infrastructure face immediate risk and should prioritize migration or network segmentation.

Why it matters: Security teams managing IIS servers, especially those running legacy .NET frameworks, need to assess their exposure to this cluster and similar China-linked operations targeting DMZ infrastructure; espionage actors maintain access for extended periods before exfiltrating data, making rapid detection and segmentation critical.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary