China Chopper is a lightweight web shell widely used for post-exploitation access on compromised web servers, especially Microsoft IIS and Exchange environments. It is commonly deployed after attackers exploit server-side vulnerabilities or abuse file upload functionality, allowing hands-on-keyboard control through a small server-side component and an operator client. The malware has been repeatedly observed in intrusions involving Microsoft Exchange exploitation, including the 2021 mass compromise of on-premises Exchange servers and later targeted exploitation of Exchange zero-days in 2022. It has also appeared in compromises of IIS-backed enterprise applications and web servers in other sectors.
China Chopper is primarily used as a persistent web-based backdoor. Once installed, it enables remote command execution and interactive administration of the compromised host. Observed operator activity through Chopper has included system and Active Directory reconnaissance, user and host enumeration, staging of data for theft, and data exfiltration. In broader intrusion chains, Chopper has served as an access mechanism preceding credential theft, lateral movement, ransomware deployment, and follow-on payload delivery by both state-linked and financially motivated actors.
The web shell has been associated with multiple Chinese-speaking intrusion sets and has frequently appeared alongside other web shells and post-exploitation tooling such as AntSword and Behinder. It has been used against organizations running vulnerable or exposed Exchange and IIS infrastructure, including government and enterprise environments. Its enduring popularity stems from its small footprint, ease of deployment, and effectiveness as a durable server-side access mechanism after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Post-compromise activity involves the rapid deployment of web shells such as AntSword and chinatso/Chopper on the underlying IIS web servers.
MSTIC observed activity related to a single activity group in August 2022 that achieved initial access and compromised Exchange servers by chaining CVE-2022-41040 and CVE-2022-41082 in a small number of targeted attacks. These attacks installed the Chopper web shell to facilitate hands-on-keyboard access, which the attackers used to perform Active Directory reconnaissance and data exfiltration.
MSTIC observed activity related to a single activity group in August 2022 that achieved initial access and compromised Exchange servers by chaining CVE-2022-41040 and CVE-2022-41082 in a small number of targeted attacks. These attacks installed the Chopper web shell to facilitate hands-on-keyboard access, which the attackers used to perform Active Directory reconnaissance and data exfiltration.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-compromise activity involves the rapid deployment of web shells such as AntSword and chinatso/Chopper on the underlying IIS web servers.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chopper is a web shell used for remote command execution and control of compromised web servers, commonly used for persistence and further exploitation.
A web shell deployed on compromised IIS servers to maintain backdoor access.
A lightweight IIS/ASP web shell used for post-exploitation interactive access (“hands-on-keyboard”) on compromised servers, enabling command execution and follow-on actions like AD reconnaissance and data exfiltration.
A web shell used post-exploitation on vulnerable Exchange servers to run commands, drop batch files and payloads, and facilitate follow-on activity including ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.