Neo-reGeorg is a publicly available web shell and tunneling tool used to proxy traffic from an external network into internal environments through a compromised web server. It is commonly deployed as a persistent web-access foothold and supports webshell-based SOCKS pivoting; reporting in the provided content specifically states it can establish a SOCKS5 proxy on a compromised web server and can create multiple TCP connections for a single session. The content also describes AES-encrypted channels and custom Base64 encoding in JSPX/JSP variants, and references deployments in ASPX, JSPX/JSP, PHP, Go, and ASHX variants. Observed deployment paths include /aspnet_client/system_web/4_0_30319/nfud.aspx, with one reported key value of 123QWEasd.
Across the cited reporting, Neo-reGeorg is used post-compromise for persistence, encrypted tunneling, and lateral access into victim networks. It appears in layered command-and-control architectures alongside tools such as Chisel reverse tunnels, GRE tunnels on compromised Cisco routers, and reverse SOCKS tooling such as Resocks/Revsocks. The content links Neo-reGeorg to multiple threat actors and campaigns, including MuddyWater, Sandworm Team during the 2022 Ukraine Electric Power Attack, APT41-linked activity observed by Kaspersky, China-nexus espionage activity involving Murky Panda/Silk Typhoon, and Unit 42’s TGR-STA-1030/UNC6619 “Shadow Campaigns.” It is also referenced in Operation Escaneo, attributed with medium confidence by CloudSEK to MexicanMafia/PanchoVilla, where it was part of a mature persistence and C2 stack targeting critical infrastructure.
Targeting associated with Neo-reGeorg in the provided content spans government, immigration, finance, telecommunications, transport, utilities, and other critical infrastructure, with activity reported in Latin America, Africa, Europe, the Middle East, and Ukraine. Specific victim examples in the content include a Portuguese government-related Exchange or mail server at mail.sef.pt hosting an active ASPX Neo-reGeorg webshell at https://mail.sef.pt/aspnet_client/system_web/4_0_30319/nfud.aspx, and another reported deployment at https://69.167.160.144/nfud.aspx. Additional indicators directly mentioned include the path pattern /aspnet_client/system_web/4_0_30319/nfud.aspx and the tunnel/webshell key 123QWEasd. The content also notes Neo-reGeorg-derived PHP shells observed by Cisco Talos, including a web shell named 401.php based on the public Neo-reGeorg codebase.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Based on these names, we were able to determine that this instance utilized a Neo-reGeorg web shell tunnel. This tool is used to proxy traffic from an external network to an internal one via an externally accessible web server.
MuddyWater was observed leveraging the Chinese-developed tool Neo-reGeorg to perform webshell-based SOCKS pivoting.
"The initial access is leveraged to deploy web shells like neo-reGeorg to establish persistence and ultimately drop a custom malware called CloudedHope."
Persistent access establishment via reverse shells (GOREVERSE) and proxy tools (Neo-reGeorg, suo5).
18 distinct techniques documented for this family, organized by ATT&CK tactic.
AES-encrypted Neo-reGeorg channel key; GZIP-compressed inner payload loaded through reflection with an obfuscated defineClass invocation.
layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels
SOCKS5 pivot through 165.22.184.26:5571 to internal 10.39.x.x systems; Chisel reverse tunnel creating SOCKS proxies on 127.0.0.1:1080–1081; internal relay node at 10.39.1.204.
Multiple SOCKS proxy layers on ports 1080, 1085, 10800, 10843, 10850, 10555, 10830
Layered architecture using a public VPS, SOCKS5 relay at 165.22.184.26, internal pivot and target subnet; per-target proxychains.conf routing.
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
The attackers then started dropping various samples on this server, notably a dropper that was pushing more compiled variants carrying the same functionality... The attackers tried to drop additional post-exploitation tools to achieve their main objectives.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell used to maintain persistence and control within compromised environments, enabling continued attacker access while blending into normal traffic.
A webshell used to establish encrypted footholds on compromised web servers for persistent access.
A webshell/tunneling tool used as part of layered command-and-control infrastructure in Operation Escaneo to support persistence and covert access.
An HTTP-tunneled SOCKS5 webshell framework used for persistence, proxying, internal SMB probing, and command-and-control over AES-encrypted and custom-encoded channels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.