China Chopper
MITRE ATT&CK: S0020 View on attack.mitre.org
Aliases: China Chopper
- Malware type
- webshell
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:37:01
Targeted industries: government-and-public-sector technology-and-telecommunications education-and-nonprofits healthcare-and-pharmaceutical financial-services
Context
China Chopper is a Web Shell hosted on Web servers to provide access back into an enterprise network that does not rely on an infected system calling back to a remote command and control server. It has been used by several threat groups.
Detection coverage
- 213 Sigma rules
Malware & tools used
- Password Guessing (attack-pattern)
- Data from Local System (attack-pattern)
- Software Packing (attack-pattern)
- Windows Command Shell (attack-pattern)
- Web Protocols (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Network Service Discovery (attack-pattern)
- Timestomp (attack-pattern)
- Web Shell (attack-pattern)
- File and Directory Discovery (attack-pattern)
Used by threat actors
- Threat Group-3390 (threat-actor)
- Fox Kitten (threat-actor)
- Mustang Panda (threat-actor)
- APT41 (threat-actor)
- GALLIUM (threat-actor)
- Leviathan (threat-actor)
- ToddyCat (threat-actor)
- HAFNIUM (threat-actor)
- BackdoorDiplomacy (threat-actor)
Reports & references
- secureworks.com — Threat Group 3390 Targets Organizations For Cyberespionage (report)
- secureworks.com — Bronze Union (report)
- Palo Alto Unit 42 — Iron Taurus (report)
- secureworks.com — Bronze Express (report)
- Mandiant — Suspected Chinese Espionage Group Targeting Maritime And Engineering Industries (report)
- secureworks.com — Bronze Mohawk (report)
- CISA — Aa21 200A (report)
- secureworks.com — Bronze President (report)
- secureworks.com — Bronze Atlas (report)
- MITRE ATT&CK — G0096 (report)
- cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
- Microsoft — Gallium Targeting Global Telecom (report)
- CISA — Aa20 259A (report)
- MITRE ATT&CK — G0125 (report)
- Microsoft — Hafnium Targeting Exchange Servers (report)
- volexity.com — Active Exploitation Of Microsoft Exchange Zero Day Vulnerabilities (report)
- reddit.com — Mass Exploitation Of Onprem Exchange Servers (report)
- blog.rapid7.com — Rapid7S Insightidr Enables Detection And Response To Microsoft Exchange 0 Day (report)
- twitter.com — 1366862946488451088 (report)
- Mandiant — Detection Response To Exploitation Of Microsoft Exchange Zero Day Vulnerabilities (report)
- CrowdStrike — Falcon Complete Stops Microsoft Exchange Server Zero Day Exploits (report)
- huntress.com — Rapid Response Mass Exploitation Of On Prem Exchange Servers (report)
- ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
- justice.gov — Two Chinese Hackers Working Ministry State Security Charged Global Computer Intrusion (report)
- Broadcom/Symantec — Witchetty Steganography Espionage (report)