China Chopper

MITRE ATT&CK: S0020 View on attack.mitre.org

Aliases: China Chopper

Malware type
webshell
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:37:01

Targeted industries: government-and-public-sector technology-and-telecommunications education-and-nonprofits healthcare-and-pharmaceutical financial-services

Context

China Chopper is a Web Shell hosted on Web servers to provide access back into an enterprise network that does not rely on an infected system calling back to a remote command and control server. It has been used by several threat groups.

Detection coverage

  • 213 Sigma rules

Malware & tools used

  • Password Guessing (attack-pattern)
  • Data from Local System (attack-pattern)
  • Software Packing (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Timestomp (attack-pattern)
  • Web Shell (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

Reports & references

  • secureworks.com — Threat Group 3390 Targets Organizations For Cyberespionage (report)
  • secureworks.com — Bronze Union (report)
  • Palo Alto Unit 42 — Iron Taurus (report)
  • secureworks.com — Bronze Express (report)
  • Mandiant — Suspected Chinese Espionage Group Targeting Maritime And Engineering Industries (report)
  • secureworks.com — Bronze Mohawk (report)
  • CISA — Aa21 200A (report)
  • secureworks.com — Bronze President (report)
  • secureworks.com — Bronze Atlas (report)
  • MITRE ATT&CK — G0096 (report)
  • cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
  • Microsoft — Gallium Targeting Global Telecom (report)
  • CISA — Aa20 259A (report)
  • MITRE ATT&CK — G0125 (report)
  • Microsoft — Hafnium Targeting Exchange Servers (report)
  • volexity.com — Active Exploitation Of Microsoft Exchange Zero Day Vulnerabilities (report)
  • reddit.com — Mass Exploitation Of Onprem Exchange Servers (report)
  • blog.rapid7.com — Rapid7S Insightidr Enables Detection And Response To Microsoft Exchange 0 Day (report)
  • twitter.com — 1366862946488451088 (report)
  • Mandiant — Detection Response To Exploitation Of Microsoft Exchange Zero Day Vulnerabilities (report)
  • CrowdStrike — Falcon Complete Stops Microsoft Exchange Server Zero Day Exploits (report)
  • huntress.com — Rapid Response Mass Exploitation Of On Prem Exchange Servers (report)
  • ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
  • justice.gov — Two Chinese Hackers Working Ministry State Security Charged Global Computer Intrusion (report)
  • Broadcom/Symantec — Witchetty Steganography Espionage (report)

External references