216.73.217.22

Agentic AI Uncovers New China-Linked Cluster OP-512

· Published 05/06/2026 20:07 · Modified 08/06/2026 08:23

Export JSON

Essential information

Published
05/06/2026 20:07
Modified
08/06/2026 08:23
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
cobalt strike efspotato gamshen ghostkit meterpreter plugx timestomping
Tags
2026-06-05 cobalt strike efspotato gamshen ghostkit meterpreter plugx timestomping
Related entities
7 indicators, 7 observables, 1 intrusion sets (apt), 19 techniques (mitre), 11 malware, 2 others

Description

A newly identified China-linked espionage cluster designated OP-512 has been discovered targeting Internet Information Services (IIS) servers through advanced AI-driven detection. The operation involves deploying a sophisticated custom web shell framework consisting of three components: a file manager with command-and-control notification channel and two cryptographically authenticated command handlers. Each deployment is cryptographically unique, utilizing RSA and RC4 encryption alongside techniques to evade signature-based detection. The attacker maintained persistence for 75 days before rapid deployment of multiple access paths, privilege escalation tools including BadPotato, SweetPotato, and , and establishment of dual notification channels through DNS and HTTP. The framework employs hex-encoded subdomain queries for self-reporting and automated builder-generated code with randomized variables. This represents the fourth China-linked cluster documented targeting legacy IIS infrast...

External references