securityonline.info 6/15/2026, 7:31:21 AM · external

New Chinese Espionage Group OP 512 Targets IIS Servers

New Chinese Espionage Group OP 512 Targets IIS Servers
CyberSIXT Evidence Panel
Primary Source reliaquest.com
Threat Actor
OP-512

THE article discusses the discovery of a new espionage group, OP-512, identified by ReliaQuest Threat Research. This group exploits vulnerabilities in Internet Information Services (IIS) servers, utilizing a custom web shell framework with unique cryptographic signatures for evading detection. OP-512 is assessed as a previously undocumented Chinese operation, employing sophisticated methods such as self-reporting DNS queries and automated command handlers.

The compromised servers are running outdated software, making them susceptible to attacks. Defenders are advised to prioritize upgrading legacy .NET frameworks and enhance behavioral detection strategies.

View Primary Source Via securityonline.info

Article by CyberSIXT