Chopper is a web shell used to maintain remote access to compromised web servers and support hands-on-keyboard post-exploitation. Operators use it to execute commands, perform system and network reconnaissance, and deploy additional backdoors or other payloads. It has been used for persistence on Windows IIS servers and extensively deployed on compromised Microsoft Exchange servers. Chopper payloads have also been detected during compromises of Linux-based Zimbra environments.
Chopper is commonly installed after exploitation of server vulnerabilities or abuse of file-upload weaknesses. In August 2022, attackers chained Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082 to install Chopper, then performed Active Directory reconnaissance and data exfiltration. DoejoCrypt ransomware attacks have begun with deployment of a Chopper variant following Exchange exploitation. UAT-6382 deployed Chopper alongside other web shells after exploiting the Cityworks vulnerability CVE-2025-0994 against United States local-government networks, supporting subsequent backdoor deployment. Chopper has also appeared in cryptocurrency-mining attacks against a South Korean medical institution and in other South Korean web-server intrusions. Its use across multiple campaigns does not establish attribution to a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled. | Microsoft Defender Antivirus detected and quarantined Chopper payloads during post-exploitation of vulnerable Zimbra servers.
Post-compromise activity involves the rapid deployment of web shells such as AntSword and chinatso/Chopper on the underlying IIS web servers.
MSTIC observed activity related to a single activity group in August 2022 that achieved initial access and compromised Exchange servers by chaining CVE-2022-41040 and CVE-2022-41082 in a small number of targeted attacks. These attacks installed the Chopper web shell to facilitate hands-on-keyboard access, which the attackers used to perform Active Directory reconnaissance and data exfiltration.
MSTIC observed activity related to a single activity group in August 2022 that achieved initial access and compromised Exchange servers by chaining CVE-2022-41040 and CVE-2022-41082 in a small number of targeted attacks. These attacks installed the Chopper web shell to facilitate hands-on-keyboard access, which the attackers used to perform Active Directory reconnaissance and data exfiltration.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once compromised the threat actors deploy various web shells such as AntSword and chinatso/Chopper, used later to spread the backdoors.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JSP-capable web shell used to provide HTTP-based remote command execution on compromised servers.
Chopper is a web shell used for remote command execution and control of compromised web servers, commonly used for persistence and further exploitation.
Web shell deployed after initial compromise and used to facilitate subsequent backdoor distribution.
A web shell deployed on compromised IIS servers to maintain backdoor access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.