China Chopper is a compact server-side webshell widely used in espionage intrusions to provide persistent remote access to compromised web servers. It is most commonly deployed on Windows-based IIS servers through ASPX or ASP variants, though PHP and JSP implementations have also been documented in broader industry reporting. Once installed, it gives an operator an interactive backdoor for executing commands on the host and can serve as a staging point for follow-on tooling, payload delivery, credential access, and lateral movement.
The malware has been repeatedly associated with China-nexus threat activity and has appeared in operations attributed to groups including HAFNIUM, APT41, and other Chinese espionage clusters. It has been observed on compromised Microsoft Exchange servers, including intrusions involving the ProxyLogon exploit chain, and on compromised websites repurposed as attacker-controlled infrastructure. In multiple cases, operators used China Chopper after initial compromise to maintain access and then deploy additional malware families such as PlugX and Quarian.
Operationally, China Chopper is valued for its small footprint, ease of deployment, and utility as a post-compromise access mechanism. It is commonly used as a durable backdoor on internet-facing servers rather than as a standalone initial infection payload. Victims have included government, telecommunications, finance, media, transport, and other sectors, reflecting its role as a general-purpose intrusion tool in targeted campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The filename OutlookEN.aspx is uncommon. It was mostly used in 2021 by Hafnium (renamed Silk Typhoon by MICROSOFT) operators to deploy the ChinaChopper webshell on Microsoft Exchange Server instances compromised through the ProxyLogon exploit chain (linked to the vulnerability CVE-2021-26855). | The filename OutlookEN.aspx is uncommon. It was mostly used in 2021 by Hafnium ... operators to deploy the ChinaChopper webshell on Microsoft Exchange Server instances compromised through the ProxyLogon exploit chain.
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | the server was indeed compromised and was hosting the ChinaChopper webshell, which was used to obtain, and later launch, the Quarian and PlugX backdoors.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE ATLAS ... Tools ... Acehash, CCleaner v5.33 backdoor, ChinaChopper, Cobalt Strike, Dicey MSDN, Dodgebox, DUSTPAN, ForkPlayground, HUC Proxy Malware (Htran)
BRONZE ATLAS ... Tools ... Acehash, CCleaner v5.33 backdoor, ChinaChopper, Cobalt Strike, Dicey MSDN, Dodgebox, DUSTPAN, ForkPlayground, HUC Proxy Malware (Htran)
Compromised websites were used as C&C servers in this attack, with ChinaChopper installed as a backdoor.
"ChinaChopper, a web shell which allows the attacker to execute commands on the victim’s machine."
"ChinaChopper, a web shell which allows the attacker to execute commands on the victim’s machine."
the server was indeed compromised and was hosting the ChinaChopper webshell, which was used to obtain, and later launch, the Quarian and PlugX backdoors.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by BRONZE ATLAS and BRONZE BARTON threat profiles.
Webshell used for post-compromise access and to stage/launch additional payloads (Quarian and PlugX in the described incident).
Web shell used for remote command execution on compromised web servers/systems; observed on machines compromised in activity attributed to Emissary Panda.
ChinaChopper is mentioned as a webshell/backdoor installed on compromised websites used as C&C infrastructure in the attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.