Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors op-512

Also known as: tracked as, persistence, remote access

Description

OP-512 operates through a multi‑faceted framework that combines classic IIS web shell tactics with modern supply‑chain compromise techniques. The group first compromises targets via credential‑free vectors such as spear‑phishing attachments or malicious npm packages. Once inside, a custom web shell—encrypted with RSA and RC4 and timestomped to avoid detection—is deployed, establishing persistence through user‑scoped systemd services on Linux or Windows Run keys. The actor then expands its foothold by executing privilege escalation tools (BadPotato, SweetPotato, EfsPotato) and creating dual notification channels over DNS and HTTP. Exfiltration is cleverly camouflaged: data, authentication tokens (*.npmrc, *.ssh), and telemetry are sent to attacker‑owned GitHub repositories using obfuscated markers, while C&C traffic flows through the public commit search API. OP‑512’s toolkit includes a range of malware such as Miasma RAT, Shai‑Hulud worm, and proprietary npm package backdoors. It also leverages legitimate runtime ecosystems (Bun) to obfuscate code execution paths. The actor employs cryptographic uniqueness for each deployment, making signature‑based detection ineffective. Tactics span the full ATT&CK matrix from initial access to exfiltration, with a clear emphasis on stealth and persistence. This evolution reflects an adaptive threat surface that blends legacy server exploitation with supply‑chain attacks, posing a sophisticated risk to enterprises worldwide.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Information technology
Aerospace
Energy
Financial services
Healthcare
Hospitality
Defense
Critical infrastructure

Targeted Countries / Regions

CN
RU
VN

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 2 hours ago

Executive Summary

OP-512 is a newly documented, China‑linked espionage cluster that uses sophisticated web shells on Microsoft IIS servers to gain persistence and exfiltrate data. The actor distributes trojanized npm packages for self‑propagation, harvests credentials from cloud and CI/CD environments, and relies on covert GitHub API channels for command and control. Its operations target government, telecommunications, IT, aerospace, energy, finance, healthcare, hospitality, defense, and critical infrastructure in China, Russia, and Vietnam.

Goals & Targeting

OP-512’s strategic objective is long‑term espionage, targeting sectors where confidential infrastructure data can be extracted for political or economic advantage. By securing persistent footholds on IIS servers and exploiting widely used npm ecosystems, the actor seeks low‑visibility persistence that allows it to conduct prolonged reconnaissance, credential harvesting, and data exfiltration across multiple industries.

Enhanced Description

Key Capabilities

  • Deploy web shells on Microsoft IIS to establish persistence
  • Transfer malicious tools into target environments via ingress tool transfer (T1105)
  • Distribute trojanized npm packages that masquerade as legitimate CLI tools for self‑propagation
  • Harvest credentials from cloud providers, CI/CD pipelines and developer workstations
  • Backdoor npm packages for execution by any victim publishing the package
  • Evade static code integrity checks by embedding legitimate‑looking schema objects
  • Persist via user‑scoped systemd services on Linux or Windows Run keys
  • Exfiltrate data and command & control via covert channels including GitHub commit search API and victim‑owned repositories with obfuscated markers
  • Use DNS and HTTP dual notification channels with cryptographically unique web shell framework
  • Employ timestomping and cryptographic obfuscation (RSA, RC4) to evade detection
  • Limit lateral spread through hop caps and canary deployment strategies

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement
Persistence
Execution
Discovery
Command And Control
Exfiltration
Privilege Escalation

ATT&CK Techniques

T1105
T1195.001
T1552
T1547.006
T1071.001
T1059.003
T1041

Software / Tooling

Miasma RAT
Shai‑Hulud worm
Mini Shai‑Hulud
BadPotato
SweetPotato
EfsPotato
Bitwarden/cli malicious package
Bun runtime
npm CLI tool
GitHub CLI

Campaigns & Victims

OP-512 operates on a moderate tempo, typically deploying the web shell and npm backdoors over a span of weeks to months. Victims are primarily high‑profile organizations across multiple critical industries in China, Russia, and Vietnam. The actor exercises tight hop limits and canary deployment tactics to avoid detection, often restricting lateral movement to controlled segments. Notable operations include large‑scale credential harvesting from CI/CD pipelines and covert exfiltration via GitHub repositories using obfuscated markers.

IOC Patterns

  • Phishing attachments in emails
  • Spoofed websites
  • Malicious npm package distribution with trojanized code
  • Credential‑free initial access vectors
  • Reversed campaign marker strings (e.g., "Shai-Hulud: Here We Go Again") in public GitHub repositories
  • Backdoored npm packages hiding obfuscated code
  • Paths to "~/.npmrc" and "~/.ssh" key files

Recommended Actions

  • Isolate and investigate promptly any incidents of spear‑phishing with malicious attachments.
  • Implement code signing checks and integrity validation for all npm packages used in the organization to guard against trojanized packages.
  • Secure CI/CD pipelines and enforce strict access controls to prevent adversaries from embedding persistence mechanisms.
  • Implement npm registry whitelisting and package signing verification.
  • Audit CI/CD pipelines to ensure secrets are not exposed or harvested.
  • Monitor GitHub repositories for malicious backdoors and suspicious commit messages.
  • Restrict use of runtime ecosystems such as Bun in build environments.
  • Enforce strong token policies and rotate NPM_TOKEN and GITHUB_TOKEN regularly.
  • Implement strict egress network controls on CI runners, limiting outbound connections to trusted registries and deployment targets.

Suggested Tags

china-linked
iis-web-shell
spear phishing
malicious attachments
backdoor persistence
credential dumping
supply chain compromise
npm package tampering
credential theft
self‑propagation
command-and-control via GitHub API
teampcp attribution
npm-based malware
credential exfiltration
ci runner security

Confidence Assessment

The available intelligence provides a high‑level view of OP-512’s capabilities and tactics, but details remain fragmented across sources. While the core techniques—web shell deployment on IIS, npm supply‑chain attacks, and covert GitHub C&C channels—are well supported, gaps exist in the actor’s full operational timeline, attribution certainty, and the complete set of infrastructure used. Continuous monitoring and analysis are required to fill these gaps.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 13 Filename 4 URL 2 Email Address 1

References

  1. unit42.paloaltonetworks.com — Cited by web research for: T1195.001
  2. www.crowdstrike.com — Cited by web research for: Leverage
  3. www.crowdstrike.com — Cited by web research for: Defense
  4. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  5. https://attack.mitre.org/techniques/T1105/ — Cited by AI analysis.

Intel Summary

7

Techniques

57

Tools

0

Campaigns

44

IOCs

0

Observed Data

6

Tactics

Tags

APT
Backdoor / C2
espionage
IIS-targeted attacks
China-linked APT
Custom malware
china-linked
iis-web-shell
spear phishing
malicious attachments
backdoor persistence
credential dumping
supply chain compromise
npm package tampering
credential theft
self‑propagation
command-and-control via GitHub API
teampcp attribution
npm-based malware
credential exfiltration
ci runner security

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.