Cybersecurity researchers have identified a previously undocumented threat cluster named OP-512, which is actively targeting internet-facing Microsoft Internet Information Services (IIS) servers. The campaign leverages a sophisticated custom web shell framework to establish persistence, execute remote commands, and maintain long-term access to compromised environments. The activity demonstrates a high degree of operational maturity and appears focused on organizations operating critical infrastructure and enterprise-facing web services. The OP-512 campaign centers on the deployment of a custom web shell framework designed specifically for Microsoft IIS environments. Once attackers gain access to a vulnerable or improperly secured IIS server, the framework enables remote command execution, file manipulation, credential harvesting, and additional payload deployment. The malware is engineered to blend with legitimate IIS processes, making detection significantly more challenging for defenders. Researchers observed the threat actors using stealth techniques to maintain persistence and evade traditional security controls. The framework supports modular functionality, allowing operators to execute commands on demand, transfer files, and establish long-term footholds within victim networks. Such access can facilitate lateral movement, data theft, espionage activities, and the deployment of additional malware. The targeting pattern suggests an interest in organizations that rely heavily on IIS-based applications and web services, particularly those operating within critical sectors.
Apache ActiveMQ users are being urged to immediately apply security updates following the disclosure of two significant vulnerabilities that could expose messaging infrastructures ...
Security researchers have uncovered a large-scale cyber campaign in which threat actors combined exploited Fortinet weaknesses, AI-assisted tooling, and custom command-and-control ...
Cybersecurity researchers have uncovered a new Android spyware strain known as Asin that appears to be targeting Arabic-speaking individuals through a series of deceptive mobile ap...