China Chopper — Malware Profile
China Chopper is a Web Shell hosted on Web servers to provide access back into an enterprise network that does not rely on an infected system calling back to a remote command and control server. It has been used by several threat groups.
MITRE ATT&CK techniques (10)
- T1005 Data from Local System
- T1027.002 Software Packing
- T1046 Network Service Discovery
- T1059.003 Windows Command Shell
- T1070.006 Timestomp
- T1071.001 Web Protocols
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1110.001 Password Guessing
- T1505.003 Web Shell
IntelFusions coverage
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16
- Stately Taurus (Mustang Panda) Conducts Two-Year Southeast Asian Government Espionage Operation: Three-DLL ToneShell Variant, ShadowPad, and Continuous File Exfiltration via Dropbox 2026-02-16
Attributed threat actors
- BackdoorDiplomacy
- Fox Kitten
- APT27
- APT41
- ToddyCat
- HAFNIUM
- GALLIUM
- Operation Soft Cell machine-inferred link
- Storm-0558 machine-inferred link
- Teleboyi machine-inferred link
- APT40
- Mustang Panda