Also known as: tracked as, persistence, remote access
OP-512 operates through a multi‑faceted framework that combines classic IIS web shell tactics with modern supply‑chain compromise techniques. The group first compromises targets via credential‑free vectors such as spear‑phishing attachments or malicious npm packages. Once inside, a custom web shell—encrypted with RSA and RC4 and timestomped to avoid detection—is deployed, establishing persistence through user‑scoped systemd services on Linux or Windows Run keys. The actor then expands its foothold by executing privilege escalation tools (BadPotato, SweetPotato, EfsPotato) and creating dual notification channels over DNS and HTTP. Exfiltration is cleverly camouflaged: data, authentication tokens (*.npmrc, *.ssh), and telemetry are sent to attacker‑owned GitHub repositories using obfuscated markers, while C&C traffic flows through the public commit search API. OP‑512’s toolkit includes a range of malware such as Miasma RAT, Shai‑Hulud worm, and proprietary npm package backdoors. It also leverages legitimate runtime ecosystems (Bun) to obfuscate code execution paths. The actor employs cryptographic uniqueness for each deployment, making signature‑based detection ineffective. Tactics span the full ATT&CK matrix from initial access to exfiltration, with a clear emphasis on stealth and persistence. This evolution reflects an adaptive threat surface that blends legacy server exploitation with supply‑chain attacks, posing a sophisticated risk to enterprises worldwide.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
OP-512 is a newly documented, China‑linked espionage cluster that uses sophisticated web shells on Microsoft IIS servers to gain persistence and exfiltrate data. The actor distributes trojanized npm packages for self‑propagation, harvests credentials from cloud and CI/CD environments, and relies on covert GitHub API channels for command and control. Its operations target government, telecommunications, IT, aerospace, energy, finance, healthcare, hospitality, defense, and critical infrastructure in China, Russia, and Vietnam.
Goals & Targeting
OP-512’s strategic objective is long‑term espionage, targeting sectors where confidential infrastructure data can be extracted for political or economic advantage. By securing persistent footholds on IIS servers and exploiting widely used npm ecosystems, the actor seeks low‑visibility persistence that allows it to conduct prolonged reconnaissance, credential harvesting, and data exfiltration across multiple industries.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
OP-512 operates on a moderate tempo, typically deploying the web shell and npm backdoors over a span of weeks to months. Victims are primarily high‑profile organizations across multiple critical industries in China, Russia, and Vietnam. The actor exercises tight hop limits and canary deployment tactics to avoid detection, often restricting lateral movement to controlled segments. Notable operations include large‑scale credential harvesting from CI/CD pipelines and covert exfiltration via GitHub repositories using obfuscated markers.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a high‑level view of OP-512’s capabilities and tactics, but details remain fragmented across sources. While the core techniques—web shell deployment on IIS, npm supply‑chain attacks, and covert GitHub C&C channels—are well supported, gaps exist in the actor’s full operational timeline, attribution certainty, and the complete set of infrastructure used. Continuous monitoring and analysis are required to fill these gaps.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
57
Tools
0
Campaigns
44
IOCs
0
Observed Data
6
Tactics