Netskope Threat Labs

Chopper

ATP Sandbox Adv. HeuristicsAV

Chopper is a web shell that gives cyberattackers remote command execution on compromised web servers, and its small size and simple interface made it a staple of Chinese speaking threat actors. Once uploaded to a vulnerable application, it lets operators browse files, run commands and database queries, and stage additional tooling on the server. Defenders should treat any Chopper detection as evidence that cyberattackers have or had full control of the affected web application.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Backdoor.Chopper
DeepScan:Generic.Chopper.C.FFFFFFFE
Dump:Generic.Chopper.C.FFFFFFFE
Dump:Generic.Chopper.C.FFFFFFFE:505D2
Generic.ASP.Chopper.A.10193F8C
Generic.ASP.Chopper.A.288EC56A
Generic.ASP.Chopper.A.6CD536C2
Generic.ASP.Chopper.A.845760AC
Generic.ASP.Chopper.A.8F6586B8
Generic.ASP.Chopper.A.9FB439BE