Skip to main content
Mallory
Back to malware
MalwareUsed by 3 actorsExploits 1 CVE

ChinaChopper

ChinaChopper is a web shell used to execute commands on a victim machine through a compromised server. The provided content states it was present on compromised systems and was used to obtain and later launch the Quarian and PlugX backdoors. In one reported intrusion linked with medium to high confidence to the Chinese-speaking actor CloudComputating, attackers exploited Microsoft Exchange CVE-2020-0688, deployed a ChinaChopper web shell, and then installed Quarian and PlugX against government targets in the Middle East and Africa. Separate reporting in the content also notes ChinaChopper on compromised machines associated with activity assessed as highly likely linked to Emissary Panda (aka TG-3390, APT27, Bronze Union); in that case the observed ChinaChopper password was "123!@ZA". FireEye telemetry cited in the content lists ChinaChopper among the most frequently detected targeted malware globally in July-December 2014. High-confidence indicators directly mentioned in the content include the web shell password "123!@ZA" in the Emissary Panda-linked case.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2020-0688Microsoft Exchange Server static validation key RCEExploited in the wild

In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | the server was indeed compromised and was hosting the ChinaChopper webshell, which was used to obtain, and later launch, the Quarian and PlugX backdoors.

via securelistsecurelist.com
THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Threat Group-3390

"ChinaChopper, a web shell which allows the attacker to execute commands on the victim’s machine."

via ncc group researchnccgroup.com
APT 27

"ChinaChopper, a web shell which allows the attacker to execute commands on the victim’s machine."

via ncc group researchnccgroup.com
CloudComputating

the server was indeed compromised and was hosting the ChinaChopper webshell, which was used to obtain, and later launch, the Quarian and PlugX backdoors.

via securelistsecurelist.com
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence1

"...deployed following exploitation of the CVE-2020-0688 vulnerability... on a Microsoft Exchange server."

Persistence

1 technique
T1505.003Web ShellEvidence2

"...was hosting the ChinaChopper webshell, which was used to obtain, and later launch, the Quarian and PlugX backdoors."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

ChinaChopper | Mallory