By The Hacker News
Publication Date: 2026-06-05 12:33:00
Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where “OP” stands for “opponent”) that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework.
ReliaQuest has assessed with moderate to high confidence that the espionage-focused activity is linked to China.
“OP-512 was highly likely conducting espionage through a compromised Internet Information Services (IIS) web server on an organization whose sector and geography align with China-linked intelligence priorities,” the company said in a report shared with The Hacker News.
Although no overlaps have been found between OP-512 and other known China-aligned adversaries, it’s the fourth such threat group after CL-STA-0048, DragonRank, and GhostRedirector to single out IIS web servers over the past 12 months. As recently as last month, Cisco Talos


![Microsoft Surface Pro with Snapdragon X2 Elite leaks with June release date [Gallery] Microsoft Surface Pro with Snapdragon X2 Elite leaks with June release date [Gallery]](https://i0.wp.com/9to5google.com/wp-content/uploads/sites/4/2026/06/microsoft-surface-pro-snapdragon-x2-leak-1.png?resize=1200%2C628&quality=82&strip=all&ssl=1)
