OP-512 Cluster Hits IIS Servers With Custom Web Shell Kit, Researchers Link Activity to China
A previously unreported intrusion set is dropping a bespoke web shell framework on Microsoft IIS servers, with espionage indicators pointing toward Beijing.

A new threat cluster tracked as OP-512 is compromising Microsoft Internet Information Services (IIS) servers and installing a custom-built web shell framework on victims, according to research published this week by ReliaQuest.
The assessment ties OP-512 to China-nexus espionage activity with moderate to high confidence.
That language matters. "Moderate to high" is the same confidence band U.S. intelligence community standards reserve for judgments that are credibly sourced and plausible but not corroborated by multiple independent streams. It is not attribution in the formal sense. It is a working hypothesis the researchers are willing to defend.
The targeting profile is consistent with prior China-linked operations against internet-facing web infrastructure. IIS, Microsoft's bundled web server, has been a recurring foothold for espionage actors because compromised instances often sit at the edge of enterprise networks and host authentication-adjacent applications. A bespoke web shell framework — rather than a recycled open-source tool like China Chopper or Behinder — suggests an operator with development resources and an interest in evading commodity detection signatures.
ReliaQuest characterizes the activity as espionage-focused. The firm has not publicly tied OP-512 to a named state-sponsored group such as APT41, Volt Typhoon, or Salt Typhoon, and the cluster designation itself signals that the analysts are not yet ready to merge it with an existing tracked actor.
For defenders, the practical question is detection coverage on IIS. Web shell deployments on IIS frequently surface as anomalous module loads, unexpected w3wp.exe child processes, or new handlers registered in applicationHost.config. Microsoft published guidance on hunting for malicious IIS modules back in 2022, and that guidance remains the most useful primary reference for blue teams reviewing exposure: see the Microsoft Security Response Center writeup on IIS backdoors.
From a disclosure standpoint, organizations that detect OP-512 activity on systems holding material nonpublic information should consider obligations under the SEC's cybersecurity incident disclosure rule at 17 CFR § 229.106, which requires Form 8-K Item 1.05 reporting within four business days of a materiality determination. Espionage intrusions are not automatically immaterial. The Division of Corporation Finance has signaled in staff statements that the materiality analysis turns on impact, not actor motive.
EU-regulated entities should separately weigh NIS2 Article 23 incident notification timelines, which require an early warning within 24 hours of awareness of a significant incident and an initial assessment within 72 hours.
The research is preliminary. No CVE has been assigned because no specific vulnerability has been attributed to initial access in the public reporting so far. ReliaQuest's analysts have indicated the investigation is ongoing.
Additional indicators of compromise are expected as the cluster is tracked further.



