OP-512 is a China-linked cyberespionage cluster targeting Microsoft Internet Information Services (IIS) infrastructure to maintain persistent access for intelligence gathering. Its observed activity includes compromise of a legacy Windows Server 2016 environment running unsupported .NET Framework 4.0. The initial access mechanism has not been conclusively established, and the victim organization's country and sector have not been publicly identified. OP-512 is tracked separately from other IIS-focused clusters, including CL-STA-0048, GhostRedirector, and DragonRank; shared techniques do not establish a common identity. The cluster deploys a custom three-component web shell framework providing file management, two independently authenticated command channels, and automated deployment reporting. Newly deployed web shells report their locations through hex-encoded DNS queries, with HTTP as a fallback. Command handlers decrypt requests with RC4 and verify RSA signatures before executing commands. Separate cryptographic keys compartmentalize access, while randomized identifiers and junk code produce distinct deployments that impede signature-based detection. The framework also manipulates creation and modification timestamps to resemble surrounding legitimate files and complicate forensic reconstruction. OP-512 reflectively loads privilege-escalation tooling, including BadPotato, SweetPotato, and EfsPotato, directly into IIS worker-process memory without writing those tools to disk. Observed commands enumerate execution identity and privileges, although successful escalation to SYSTEM was not established. Persistent web shells allow tooling to reload after IIS automatically restarts terminated worker processes. Malicious ASP.NET compilation artifacts can also remain after source web shells are removed. Earlier web shell activity on the same compromised host was observed approximately 75 days before the principal incident.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked espionage cluster targeting IIS servers using a custom web shell framework with cryptographically unique deployments, self-reporting web shell location via DNS with HTTP fallback, in-memory privilege escalation tooling, and anti-detection measures such as timestomping and randomized code generation.
A likely China-linked espionage cluster conducting long-term intelligence-gathering via a compromised IIS web server, using a custom web shell framework with cryptographically unique payloads, encrypted access controls, centralized management, persistent access, privilege escalation, and multiple command channels.
A newly identified espionage cluster suspected of having ties to China that targets Internet Information Services (IIS) web servers using a custom, cryptographically unique web shell framework, in-memory privilege escalation tooling, and persistence techniques designed to evade detection and survive process restarts.
Espionage-focused activity cluster targeting Microsoft IIS servers using a custom multi-component web shell framework for remote access and defense evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.