QuickLook: OP-512 in Context: One Cluster, a Whole Ecosystem
An update to the GBHackers article — what’s confirmed, what’s contested, and where the attribution actually leads.
Initial Article
BOTTOM LINE UP FRONT
One cluster, five adjacent claimants, and a single thread tying them together that turns out not to hold weight. ReliaQuest’s OP-512 (a custom RSA/RC4 IIS web-shell framework) reads like a purpose-built espionage tool with no match to any known actor. Unit 42’s CL-STA-0048 is the closest public comparison — but the overlap is one shared technique, not shared tradecraft. Trend Micro’s Earth Lamia, EclecticIQ’s SAP campaign, and Sysdig’s UNC5174 all orbit the same ecosystem with contested, reused infrastructure. For threat-intel practitioners: OP-512 should stay a distinct cluster; the real pivots are two infrastructure neighborhoods, not actor names; and the shared tool pool (VShell, SNOWLIGHT, Supershell, Cobalt Strike) is a false-merge trap, not evidence. The lesson is older than this case — attribution is harder than finding the malware. [^1]
Analyst Comments
SECTION 1: THE SIX REPORTS AT A GLANCE
The Ecosystem Story
OP-512 (ReliaQuest, June 2026) is the subject. A China-linked espionage cluster running a custom three-part IIS web-shell framework — one .aspx self-reporting file manager plus two .ashx RSA/RC4 command handlers, per-deployment cryptographic uniqueness, timestomping, hex-encoded DNS C2. Assessed China-linked at moderate-to-high confidence, with no overlap to any known actor. [^1]
CL-STA-0048 (Unit 42, January 2025) is the closest public comparison. China-nexus espionage against South Asian telecom and government, pivoting IIS → Tomcat → MSSQL, leaning on PlugX, Cobalt Strike, and Hex Staging. It shares hex-encoded DNS with OP-512 — but uses it for exfiltration, where OP-512 uses it to report deployment location. [^2]
The SAP campaign (EclecticIQ, May 2025) splits CVE-2025-31324 activity across three actors — CL-STA-0048, UNC5221, UNC5174 — plus an uncategorized scanner. It re-sights CL-STA-0048 via 43.247.135[.]53 and sentinelones[.]com. [^3]
Earth Lamia (Trend Micro, May 2025) is the consolidator. China-nexus since 2023, custom PULSEPACK backdoor, and it absorbs REF0657, parts of STAC6451, and parts of CL-STA-0048 — re-attributing infrastructure other vendors assigned elsewhere. [^4]
Earth Lamia and CL-STA-0048 are not formally merged — Trend partially absorbs the activity at medium confidence, citing a 2024-to-2025 time gap in the shared infrastructure.
UNC5174 (Sysdig / The Hacker News, April 2025) rounds out the neighborhood. China-nexus, aka Uteus, exploiting Ivanti/F5/ScreenConnect, running the SNOWLIGHT → GOHEAVY → Supershell chain with VShell and Sliver. [^5]
SECTION 2: THE ONE LINK — AND WHY IT DOESN’T HOLD
The entire bridge from OP-512 to the rest of the ecosystem is a single technique: hex-encoded DNS subdomain queries. Both OP-512 and CL-STA-0048 use it. [^1] [^2]
But every vendor in this set characterizes the technique as ecosystem-wide — common across Chinese intrusion sets and unsuitable as a standalone attribution marker. And the two clusters use it for different operational purposes: CL-STA-0048 encodes stolen data for exfiltration; OP-512 encodes a web shell’s own URL to report where it landed. Same encoding, different intent.
Strip the shared technique out — as consistency demands, since it’s a pool behavior — and OP-512’s tie to the ecosystem rests on targeting convergence (legacy IIS) and broad victimology, not on tradecraft continuity.
Meanwhile, OP-512’s defining feature — the per-deployment-unique RSA/RC4 .ashx command framework — appears in no other report. That asymmetry is the whole case: a strong, unique identifier present in OP-512 and absent everywhere else, against one weak, shared technique present in both.
SECTION 3: WHAT IS ACTUALLY CONFIRMED
Relationships, ranked by what the evidence supports:
OP-512 ↔ CL-STA-0048 — LOW. Shared hex-encoded DNS technique only; ecosystem-wide, different purpose. [^1] [^2]
CL-STA-0048 ↔ DragonRank — MEDIUM. PlugX component overlap; Unit 42 kept them separate. [^2]
Earth Lamia = REF0657 — HIGH. Trend merges them via cert pivot (chrome-online[.]site → 149.104.23[.]176). [^4]
UNC5174 ↔ Supershell — HIGH. SNOWLIGHT fetches GOHEAVY from Supershell infrastructure; Mandiant and Sysdig reporting. [^5]
CL-STA-0048 ↔ Supershell — HIGH. 206.237.0[.]49 observed by Unit 42. [^2]
Earth Lamia ↔ CL-STA-0048 — MEDIUM. Trend partially absorbs the activity. [^4]
OP-512 ↔ Earth Lamia — NONE. No shared malware or infrastructure.
The pattern is clear: everything stronger than LOW lives downstream of CL-STA-0048, among clusters the vendors themselves decline to fully merge. OP-512 sits upstream and alone.
SECTION 4: INFRASTRUCTURE — THE REAL PIVOTS
The highest-value indicators are the ones that recur across reports under different actor labels. They persist even when vendors disagree about attribution, which is exactly what makes them better leads than any single name.
43.247.135.x — Unit 42, EclecticIQ, Trend. [^2] [^3] [^4] Reappears under multiple labels; .53 and .106 sit in the same /24.
sentinelones[.]com — the most contested domain. A Cobalt Strike C2 typosquat, claimed by CL-STA-0048 and Earth Lamia both. [^2] [^4]
206.237.0[.]49 — Supershell infrastructure per Unit 42, also in the UNC5174 chain. [^2] [^5]
206.237.x / 206.238.x — an infrastructure neighborhood where Earth Lamia C2s cluster. [^2] [^4]
103.30.76[.]206 — the same IP, attributed to UNC5174 by EclecticIQ and to Earth Lamia by Trend. [^3] [^4]
These are strong enrichment leads, not proof of common operational control. A cross-vendor IP recurrence tells you where to pivot; it does not tell you whose hand is on the keyboard.
SECTION 5: THE FALSE-MERGE TRAPS
Every report warns, explicitly or in effect, against treating shared tooling as attribution evidence. These prove ecosystem membership, not actor identity:
SNOWLIGHT · VShell · Supershell · Sliver · Cobalt Strike · Potato Suite · DLL sideloading · hex-encoded DNS · dnslog.pw · ceye.io · oastify.com
The sharpest illustration is SNOWLIGHT. EclecticIQ attributed 103.30.76[.]206 to UNC5174 because the chain delivered SNOWLIGHT. [^3] Trend re-attributed the same IP to Earth Lamia at high confidence, noting SNOWLIGHT is one of the default stagers in the VShell framework — anyone using the framework generates it, so it can’t carry attribution weight. [^4] Sysdig independently makes the same point: these open-source tools are adopted precisely to blur attribution. [^5]
If a single shared stager can drag one IP across two named actors, no shared tool should ever be the load-bearing element in a merge.
SECTION 6: ANTICIPATING THE COUNTER-ARGUMENT
The distinct-cluster verdict has three soft spots. Naming them is what makes the verdict defensible rather than merely cautious.
The adjacency claim is thinner than it looks. Apply the false-merge skepticism consistently and the one technique linking OP-512 outward — hex-encoded DNS — is itself a pool behavior. [^1] [^2] OP-512 may be less “inside” the ecosystem than contemporary with it and aimed at the same attack surface. Four China-linked clusters converging on legacy IIS in twelve months is still meaningful — but it’s convergence, not kinship. [^1]
“China-nexus” is an inherited assumption. This whole analysis debates which cluster OP-512 is while treating the China attribution as settled. It isn’t forensic proof — it’s ReliaQuest’s moderate-to-high-confidence analytic judgment on victimology and targeting, with no known-actor match. [^1] Reasonable, corroborated, but the one premise left un-interrogated.
The retooling hypothesis can’t be disproved. The strongest case against keeping OP-512 separate is the one ReliaQuest itself raises: that OP-512 is an existing cluster (CL-STA-0048 the candidate) that completely re-tooled. [^1] “No shared framework” is exactly what deliberate retooling would produce.
Why distinct-tracking still wins: you track separately precisely because continuity can’t be confirmed. Merging on suspicion of retooling — with no shared framework, crypto, artifacts, or infrastructure — manufactures a super-actor from absence of evidence. The retooling hypothesis is a reason to watch the merge bar, not to merge now.
SECTION 7: WHAT EACH VENDOR ISN’T TELLING YOU
ReliaQuest (OP-512). The attribution rests on victimology and targeting alignment, not forensic indicators — and “no known-actor overlap” is doing a lot of work for a cluster surfaced by an AI correlation engine. The IOCs are flagged as intrusion-specific and likely to rotate, so the published indicators have a short shelf life by the vendor’s own admission. [^1]
Unit 42 (CL-STA-0048). Names a DragonRank PlugX overlap but stops short of explaining why it isn’t a merge — the reader gets the data point without the reasoning. [^2]
EclecticIQ (SAP campaign). Splits activity across three actors partly on tooling that Trend later shows is unreliable for exactly that purpose. The UNC5174 attribution on 103.30.76[.]206 is the weakest link. [^3]
Trend Micro (Earth Lamia). The most aggressive consolidator — absorbs REF0657, STAC6451, and CL-STA-0048 activity — but several of those merges ride on medium-confidence infrastructure with acknowledged time gaps. Aggressive clustering risks the opposite error from EclecticIQ’s: over-merging. [^4]
Sysdig (UNC5174). Strong on the malware chain, but the whole report rests on tooling (SNOWLIGHT, VShell) that it simultaneously admits is open-source and attribution-blurring. [^5]
SECTION 8: HUNTING RECOMMENDATIONS
For Expanding OP-512 Specifically
Hunt the framework, not the IOCs. Search Shodan/Censys for internet-facing IIS hosts whose .ashx endpoints return encrypted/non-standard bodies, paired with the legacy Windows Server 2016 / .NET 4.0 surface. This is the only pivot that finds new OP-512 victims rather than adjacent infrastructure. [^1]
For Mapping the Ecosystem
Pivot the two neighborhoods. Run passive DNS and certificate transparency against 43.247.135.x and 206.237.x / 206.238.x. A real hit is a host that also shows OP-512 framework behavior — not mere co-residence. [^2] [^4]
For Attribution-Quality Evidence
Chase the developer artifacts. Pivot the VShell sample hash, the mscoree.dll loader, and the distinctive Voidmaw-master\Dll1.pdb string in malware repositories. For OP-512, the prize is a reused RSA public key across two deployments — by design it should never recur, so a match is a strong identity link. [^4]
What Not To Do
Don’t pivot on pool tools. A hit on SNOWLIGHT, VShell, Supershell, or an OOB-testing domain proves ecosystem membership, not identity. Treated as a merge signal, it collapses distinct clusters into a false super-actor.
SECTION 9: THE META-ANALYSIS
Five Vendors, Five Slices
Each report views one shared China-nexus enterprise-app-exploitation ecosystem through its own telemetry. ReliaQuest sees a distinct IIS framework. Unit 42 sees a South Asian espionage campaign. EclecticIQ sees three actors in a SAP intrusion. Trend sees one big actor absorbing several. Sysdig sees a Linux malware chain. They are slicing the same animal from different angles — which is why the same indicators carry conflicting labels.
The Convergence
What the reports agree on:
These actors target public-facing enterprise apps (IIS, SAP, Tomcat, MSSQL, Ivanti)
They draw from a shared, largely open-source tool pool
That shared tooling is deliberately attribution-blurring
Infrastructure recurs faster than it can be cleanly attributed
The Divergence
EclecticIQ splits; Trend merges. That tension — over-attribution versus over-consolidation — is the live methodological fault line, and OP-512 sits right on it. ReliaQuest’s choice to hold it separate is the conservative call, and under genuine uncertainty, conservative is correct.
For practitioners: read all six reports, trust none completely on attribution, and treat every shared indicator as a question rather than an answer. The cluster you can’t merge is often more honest than the one you can.
READ THE SOURCES
[^1]: ReliaQuest — Agentic AI Uncovers New China-Linked Cluster OP-512, 2026-06-05. https://reliaquest.com/blog/threat-spotlight-reliaquests-agentic-ai-uncovers-new-china-linked-cluster-op-512
[^2]: Unit 42 (Palo Alto) — CL-STA-0048: Espionage Against High-Value Targets in South Asia, 2025-01-29. https://unit42.paloaltonetworks.com/espionage-campaign-targets-south-asian-entities/
[^3]: EclecticIQ — China-Nexus Actors Exploit SAP NetWeaver CVE-2025-31324, 2025-05-13. https://blog.eclecticiq.com/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures
[^4]: Trend Micro — Earth Lamia Develops Custom Arsenal to Target Multiple Industries, 2025-05-27. https://www.trendmicro.com/en_gb/research/25/e/earth-lamia.html
[^5]: Sysdig via The Hacker News — Chinese Hackers Target Linux Systems Using SNOWLIGHT and VShell, 2025-04-15. https://thehackernews.com/2025/04/chinese-hackers-target-linux-systems.html
[^6]: The Hacker News — New Threat Cluster OP-512 Targets Microsoft IIS Servers, 2026-06-05. https://thehackernews.com/2026/06/new-threat-cluster-op-512-targets.html
[^7]: GBHackers — China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS. https://gbhackers.com/china-linked-espionage-aspx-ashx-shells/



