China Chopper is a compact client/server web shell used to obtain remote control of compromised web servers and maintain access to victim networks. Its server-side payload is controlled through a client application and supports remote command execution, file uploads, security scanning, and brute-force password guessing against authentication portals. Variants include PHP and ASPX implementations, with encrypted and obfuscated versions observed in intrusions. Attackers use it to execute additional tools and payloads, including PowerShell commands that download other malware.
China Chopper is commonly deployed after exploitation of internet-facing server applications. Documented deployments include exploitation of Microsoft SharePoint vulnerability CVE-2019-0604 and the Microsoft Exchange vulnerabilities CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. It has been used by HAFNIUM, GALLIUM, Flax Typhoon, Weaver Ant, Chinese Ministry of State Security-affiliated actors, and the Iran-based actor associated with Pioneer Kitten and UNC757. Financially motivated Prometei operators have also used it to deliver cryptomining malware, so its presence alone does not establish attribution. Deployments have affected government, telecommunications, defense industrial base, and commercial organizations. In a telecommunications intrusion attributed to Weaver Ant, China Chopper supported persistent remote access lasting more than four years.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A recently patched, high-severity vulnerability in Microsoft SharePoint (CVE-2019-0604) that allows remote code-execution is being increasingly exploited in the wild, according to researchers – possibly by the FIN7 group, among others.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | We assess with moderate confidence that the initial infection vector is exploitation of ProxyShell vulnerabilities in Microsoft Exchange Server through the deployment of China Chopper web shell.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | We assess with moderate confidence that the initial infection vector is exploitation of ProxyShell vulnerabilities in Microsoft Exchange Server through the deployment of China Chopper web shell.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | We assess with moderate confidence that the initial infection vector is exploitation of ProxyShell vulnerabilities in Microsoft Exchange Server through the deployment of China Chopper web shell.
In early March 2021, APT actors exploited CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 to install 17 China Chopper webshells on the Exchange Server.
In early March 2021, APT actors exploited CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 to install 17 China Chopper webshells on the Exchange Server.
In early March 2021, APT actors exploited CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 to install 17 China Chopper webshells on the Exchange Server.
In early March 2021, APT actors exploited CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 to install 17 China Chopper webshells on the Exchange Server.
ProxyNotShell Exchange vulnerabilities (CVE-2022-41040 [CVSS:8.8], CVE-2022-41082 [CVSS:8.0])... CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability, that would allow an attacker to run PowerShell in the context of the compromised system. | In known real-world attacks, threat actors have exploited the pair of vulnerabilities to deploy the China Chopper webshell on impacted Microsoft Exchange servers.
ProxyNotShell Exchange vulnerabilities (CVE-2022-41040 [CVSS:8.8], CVE-2022-41082 [CVSS:8.0])... CVE-2022-41082 allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker. | In known real-world attacks, threat actors have exploited the pair of vulnerabilities to deploy the China Chopper webshell on impacted Microsoft Exchange servers.
eSentire is aware of reports of the widespread exploitation of the critical NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) vulnerability CVE-2023-3519 (CVSS: 9.8). It is a Remote Code Execution (RCE) vulnerability that may be exploited by a remote and unauthenticated threat actor to achieve code execution. | Shadowserver has confirmed that attacks resulted in the deployment of the ChinaChopper webshell, a tool known to be used by Chinese affiliated threat actor groups in attacks related to both espionage and ransomware deployment.
On June 2nd, 2022, Atlassian disclosed a critical vulnerability impacting the Confluence collaboration tool, tracked as CVE-2022-26134; active exploitation of the vulnerability has been confirmed. CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. | Attacks observed by Volexity resulted in the deployment of the open-source webshell BEHINDER, a file upload webshell, and the China Chopper webshell.
China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
The China Chopper actor activity starts with the download and execution of two exploit files which attempt to exploit the Windows vulnerabilities CVE-2015-0062, CVE-2015-1701 and CVE-2016-0099 to allow the attacker to modify other objects on the server. | China Chopper is a web shell that allows attackers to retain access to an infected system using a client side application which contains all the logic required to control the target.
CVE-2021-27857: Is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
24 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“China Chopper is a web shell hosted on a web server and is mainly used for web application attacks; it is configured in a client/server relationship.”
We assess with moderate confidence that the initial infection vector is exploitation of ProxyShell vulnerabilities in Microsoft Exchange Server through the deployment of China Chopper web shell.
Multi-functionality: Upload/Download/Delete files; Enumerate local drives; Initiate shell session. Parameters: z0, z1, z2. China Chopper?
Multi-functionality: Upload/Download/Delete files; Enumerate local drives; Initiate shell session. Parameters: z0, z1, z2. China Chopper?
Weaver Ant maintained persistent access to an internal server for four years using the China Chopper web shell.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Limited exploitation of these vulnerabilities has been ongoing since at least September 2022. | CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability, that would allow an attacker to run PowerShell in the context of the compromised system.
A web shell provides an operator with a way to execute commands (input) and receive its results (output) on a target system.
CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. Exploitation of this vulnerability would allow an unauthenticated and remote actor to execute code on vulnerable devices
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
147 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell cited for comparison; it supports HTTP POST command execution, file operations, and command-terminal access through web servers.
Lightweight web shell referenced as a common reusable attacker tool for remote access and command execution.
A widely reused generic web shell used as a comparison baseline for more application-specific implants.
A widely used webshell installed on vulnerable Exchange servers to provide backdoor access after exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.