ChunkyTuna is a PHP web shell used by an Iran-based threat actor correlated with Pioneer Kitten / UNC757 in campaigns targeting U.S. federal agencies and organizations in the information technology, government, healthcare, financial, insurance, and media sectors. It was deployed after exploitation of internet-facing systems, particularly vulnerable Pulse Secure VPN, Citrix NetScaler, and F5 BIG-IP devices, including CVE-2019-11510, CVE-2019-11539, CVE-2019-19781, and CVE-2020-5902. The malware is described as allowing chunked-transfer-encoding HTTP that tunnels TCP streams over HTTP, and it supports reverse connections to a server with the intent to exfiltrate data. CISA/FBI reporting states the actor used ChunkyTuna alongside other web shells such as Tiny and China Chopper, as well as tunneling tools including FRP/FRPC, Chisel, and ngrok, to maintain persistence and remote access for extended periods. A modified ChunkyTuna sample was identified in CISA malware analysis as a PHP web shell using custom HTTP headers, including X-Pwd, for access control. Reported indicators include a modified ChunkyTuna sample with SHA256 8c9aeedeea37ee88c84b170d9cd6c6d83581e3a57671be0ba19f2c8a17bd29f3, and advisory-referenced NetScaler file paths associated with web shell deployment such as /netscaler/ns_gui/admin_ui/rdx/core/css/images/css.php.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781. | The threat actor also relies heavily on open-source and operating system (OS) tooling to conduct operations, such as ngrok; fast reverse proxy (FRP); Lightweight Directory Access Protocol (LDAP) directory browser; as well as web shells known as ChunkyTuna, Tiny, and China Chopper.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor also relies heavily on open-source and operating system (OS) tooling to conduct operations, such as ngrok; fast reverse proxy (FRP); Lightweight Directory Access Protocol (LDAP) directory browser; as well as web shells known as ChunkyTuna, Tiny, and China Chopper.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.