Neo-reGeorg is an open-source webshell-based tunneling tool used to establish SOCKS5 proxy access through a compromised, externally reachable web server. Server-side variants support common web application environments, including ASP.NET, Java JSP/JSPX, and PHP. An operator connects with a client component that encapsulates proxied TCP traffic in HTTP or HTTPS requests, enabling access to internal systems reachable from the compromised server and supporting multiple TCP connections within a session. Implementations may use encrypted channels and custom encoding, providing a covert pivoting mechanism and persistent web-based foothold. Neo-reGeorg has been used in intrusions by multiple espionage and financially motivated threat actors, including China-nexus groups such as APT41, MURKY PANDA, and TGR-STA-1030, as well as MuddyWater and Sandworm-linked activity. It has appeared following exploitation of internet-facing appliances and servers, including email infrastructure, and in campaigns targeting government, critical infrastructure, telecommunications, finance, and other organizations worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On some of the compromised Ivanti CSA appliances investigated, webshells related to the open-source tool Neo-reGeorg... were found.
MURKY PANDA has deployed web shells including Neo-reGeorg during their cyberespionage operations... MURKY PANDA heavily relies on exploiting internet-facing appliances to gain initial access and has frequently deployed web shells — including the Neo-reGeorg web shell frequently used by China-nexus adversaries — to establish persistence.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Based on these names, we were able to determine that this instance utilized a Neo-reGeorg web shell tunnel. This tool is used to proxy traffic from an external network to an internal one via an externally accessible web server.
MuddyWater was observed leveraging the Chinese-developed tool Neo-reGeorg to perform webshell-based SOCKS pivoting.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
AES-encrypted Neo-reGeorg channel key; GZIP-compressed inner payload loaded through reflection with an obfuscated defineClass invocation.
layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels
Multiple SOCKS proxy layers on ports 1080, 1085, 10800, 10843, 10850, 10555, 10830
Layered architecture using a public VPS, SOCKS5 relay at 165.22.184.26, internal pivot and target subnet; per-target proxychains.conf routing.
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
Neo-reGeorg... [was deployed] using third-party compromised systems as reverse tunnels to proxy further malicious actions.
The attackers then started dropping various samples on this server, notably a dropper that was pushing more compiled variants carrying the same functionality... The attackers tried to drop additional post-exploitation tools to achieve their main objectives.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web-shell-based tunneling utility used to create encrypted SOCKS/HTTP reverse tunnels through compromised web servers, obscuring the operators' origin while proxying subsequent malicious activity.
A webshell used to maintain persistence and control within compromised environments, enabling continued attacker access while blending into normal traffic.
A webshell used to establish encrypted footholds on compromised web servers for persistent access.
A webshell/tunneling tool used as part of layered command-and-control infrastructure in Operation Escaneo to support persistence and covert access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.