ATT&CKSoftwareChina Chopper

China Chopper

S0020

Malware.View on attack.mitre.org

About this malware

China Chopper is a Web Shell hosted on Web servers to provide access back into an enterprise network that does not rely on an infected system calling back to a remote command and control server. It has been used by several threat groups.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1005
Data from Local System

China Chopper's server component can upload local files.

T1027.002
Software Packing

China Chopper's client component is packed with UPX.

T1046
Network Service Discovery

China Chopper's server component can spider authentication portals.

T1059.003
Windows Command Shell

China Chopper's server component is capable of opening a command terminal.

T1070.006
Timestomp

China Chopper's server component can change the timestamp of files.

T1071.001
Web Protocols

China Chopper's server component executes code sent via HTTP POST commands.

T1083
File and Directory Discovery

China Chopper's server component can list directory contents.

T1105
Ingress Tool Transfer

China Chopper's server component can download remote files.

T1110.001
Password Guessing

China Chopper's server component can perform brute force password guessing against authentication portals.

T1505.003
Web Shell

China Chopper's server component is a Web Shell payload.

Groups that use it9

Campaigns0

None recorded.

References5

  1. CISA AA21-200A APT40 July 2021 Open source
    CISA. (2021, July 19). (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department. Retrieved August 12, 2021.
  2. Dell TG-3390 Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.
  3. FireEye Periscope March 2018 Open source
    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.
  4. Lee 2013 Open source
    Lee, T., Hanzlik, D., Ahl, I. (2013, August 7). Breaking Down the China Chopper Web Shell - Part I. Retrieved March 27, 2015.
  5. Rapid7 HAFNIUM Mar 2021 Open source
    Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.