Godzilla web shell
-
Researchers link new OP-512 cluster to IIS server espionage campaign
Researchers found a new China-linked threat cluster, OP-512, targeting Microsoft IIS servers with a custom web shell framework. The activity used timestomping, self-reporting shells and attempted privilege escalation on a legacy Windows Server 2016 host.
-
KnowledgeDeliver flaw used in zero-day attacks to deploy Godzilla web shell
A zero-day flaw in Digital Knowledge’s KnowledgeDeliver learning management system was used to deploy the Godzilla web shell and later Cobalt Strike Beacon. The issue stemmed from hard-coded ASP.NET machine keys and affected deployments before Feb. 24, 2026.


