China Chopper is a compact web shell and web-based backdoor used to maintain remote access to compromised web servers. It is commonly implemented as a minimal server-side script that accepts attacker-supplied code or commands over HTTP, while a separate client provides a richer operator interface for command execution, file management, database interaction, and remote administration. Variants have been observed across multiple web application stacks, including PHP, classic ASP, and ASP.NET, and it has been widely associated with compromises of IIS- and other web-server environments.
The malware is notable for its small server component and client/server operating model. The server-side component executes code delivered in web requests, commonly via HTTP POST parameters, enabling arbitrary command execution on the host. Reported capabilities include file transfer and creation, virtual terminal access, interaction with database servers, timestamp manipulation for defense evasion, and use as a staging point for additional payloads or archived data prior to exfiltration. In operational use, China Chopper frequently serves as a persistence mechanism on internet-facing servers and as a lightweight post-exploitation foothold during lateral movement.
China Chopper has been used by numerous threat actors and is not unique to any single cluster, though it is strongly associated with Chinese espionage operations and broader China-nexus intrusion activity. It has been reported in campaigns involving groups such as GALLIUM, BRONZE UNION, BRONZE PRESIDENT, Tropic Trooper, APT41/Wicked Panda, and Red Menshen, among others. It has also appeared in major exploitation waves involving vulnerable public-facing applications and servers, including Microsoft Exchange and SharePoint compromises, as well as intrusions leveraging exposed web applications, service desk platforms, and content management systems.
Observed infection vectors center on exploitation of vulnerable or misconfigured web-facing systems and subsequent placement of the web shell on the server. Once deployed, operators use it for persistent access, command execution, internal reconnaissance, credential-access follow-on activity via other tools, malware staging, and movement deeper into victim environments. Targeting has spanned telecommunications, government, defense, media, academia, technology, and other sectors worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. According to our telemetry, the newly discovered web shell was also associated with a campaign leveraging CVE-2023-26360 early this year targeting vulnerable servers in the Middle East. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper Mitigation: Update affected Microsoft products with the latest security patches | CVE-2019-0604 ... Associated Malware: China Chopper | CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper
CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 allow for remote code execution. CVE-2021-26858 and CVE-2021-27065 are similar post-authentication arbitrary write file vulnerabilities in Exchange. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could write a file to any path on the server.
Microsoft has released out-of-band security updates to address four vulnerabilities in Exchange Server: CVE-2021-26855 allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange Server. The vulnerability exploits the Exchange Control Panel (ECP) via a Server-Side Request Forgery (SSRF).
CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 allow for remote code execution. CVE-2021-26858 and CVE-2021-27065 are similar post-authentication arbitrary write file vulnerabilities in Exchange. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could write a file to any path on the server.
CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 allow for remote code execution... CVE-2021-26857 is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781.
The threat actors then used BEHINDER to install the China Chopper web shell and a simple file upload tool as backups.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
"In summer 2018, threat actors were observed targeting public-facing web servers that were vulnerable to CVE-2017-3066. The activity was related to a vulnerability in the web application development platform Adobe ColdFusion, which enabled remote code execution."
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
Threat actors are actively exploiting a recently disclosed critical vulnerability, tracked as CVE-2026-1731 (CVSS score: 9.9), in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The bug could allow an unauthenticated attacker to send specially crafted requests and run operating system commands remotely, without logging in.
16 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Using these credentials, the operators accessed a management VPN and moved laterally to an OSS application on the transport network. This system’s web management interface was infected with the China Chopper backdoor, a well-known web shell associated with Chinese APT operations, which provided persistent access.
"China Chopper Commonly used and widely shared web shell used by several threat actors. Not unique to GALLIUM."
The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
Microsoft Exchange Incident “China Chopper” ASPX Webshell filenames ... Unit 42 Analyzing Attacks Against Microsoft Exchange Server With China Chopper Webshells
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
China Chopper is commonly used by Chinese threat actors, which are known to deploy the webshell through different vectors, such as exploiting web server vulnerabilities, cross-site scripting, or SQL injections. | We observed compromises of web servers and MySQL database servers exposed to the Internet as initial indicators of the DragonSpark attacks.
The term shell refers to the command-line interface (CLI)... Its original purpose is to execute arbitrary commands on a remote system.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The module exhibits characteristics commonly associated with malicious activity, including obfuscation and dynamic execution of commands... a Base64 string is decoded and then executed via dynamic evaluation using JavaScript.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
adding attack.discovery since rule already have tags t1018, t1033 & t1087.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
83 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell client/management tool associated with lightweight 'OneShell' server-side implants and widely used to operate compromised web servers.
A web shell/backdoor cited as a commonly reused tool in Chinese state-sponsored intrusions, especially relevant to external-facing server compromise.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
A web shell/backdoor used to maintain persistent access on compromised web management interfaces and staging systems during lateral movement in the telecom intrusions described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.