China Chopper is a web shell used to provide remote, interactive post-compromise access to web servers. It has been deployed after exploitation of Microsoft Exchange Server, Zimbra Collaboration Suite, Trimble Cityworks, and file-upload vulnerabilities, including on IIS and Java application-server environments. Operators use it to execute commands and conduct host, network, account, and Active Directory reconnaissance; it can also maintain access following initial server compromise. China Chopper has appeared in activity attributed to diverse criminal and suspected state-sponsored operators, including Chinese-speaking intrusion clusters, rather than being exclusive to a single threat actor. It has been observed on Windows web servers and on Linux-hosted Java/Zimbra server environments, often alongside other web shells and follow-on tooling used for lateral movement and data collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled. | Microsoft Defender Antivirus detected and quarantined Chopper payloads during post-exploitation of vulnerable Zimbra servers.
Post-compromise activity involves the rapid deployment of web shells such as AntSword and chinatso/Chopper on the underlying IIS web servers.
MSTIC observed activity related to a single activity group in August 2022 that achieved initial access and compromised Exchange servers by chaining CVE-2022-41040 and CVE-2022-41082 in a small number of targeted attacks. These attacks installed the Chopper web shell to facilitate hands-on-keyboard access, which the attackers used to perform Active Directory reconnaissance and data exfiltration.
MSTIC observed activity related to a single activity group in August 2022 that achieved initial access and compromised Exchange servers by chaining CVE-2022-41040 and CVE-2022-41082 in a small number of targeted attacks. These attacks installed the Chopper web shell to facilitate hands-on-keyboard access, which the attackers used to perform Active Directory reconnaissance and data exfiltration.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-compromise activity involves the rapid deployment of web shells such as AntSword and chinatso/Chopper on the underlying IIS web servers.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JSP-capable web shell used to provide HTTP-based remote command execution on compromised servers.
Chopper is a web shell used for remote command execution and control of compromised web servers, commonly used for persistence and further exploitation.
A web shell deployed on compromised IIS servers to maintain backdoor access.
A lightweight IIS/ASP web shell used for post-exploitation interactive access (“hands-on-keyboard”) on compromised servers, enabling command execution and follow-on actions like AD reconnaissance and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.