Regin is a highly sophisticated, multi-stage modular cyber-espionage platform associated with long-term intelligence collection operations and widely assessed as nation-state-grade tooling. Public reporting has linked it to Western intelligence services, but definitive attribution has not been established with certainty. Activity associated with Regin has been observed from at least 2003 and remained active into the 2010s.
Regin is designed to provide deep, stealthy remote control across victim environments. Its architecture uses staged deployment, with early stages acting as loaders for later components, and stores important functionality in encrypted virtual file systems. On some systems, later-stage components have been stored in NTFS Extended Attributes or in the Windows Registry to reduce visibility. Analysis of kernel components shows advanced Windows internals expertise, including custom virtual file system abstractions, IRQL-aware synchronization, and direct use of kernel I/O routines.
The platform supports a broad espionage and post-compromise feature set. Confirmed capabilities include keylogging, remote registry modification, encrypted command-and-control, peer-to-peer communications between infected hosts, and lateral movement within victim networks through replication to remote systems via administrative shares. Regin has also been described as maintaining stealthy persistence through backdoor functionality and modular communications components that route traffic internally through infected machines, reducing conspicuous outbound connections.
Regin is notable for operations against telecommunications providers and for modules associated with GSM network monitoring. Investigations recovered activity consistent with compromise of a GSM Base Station Controller environment, including collection of engineering credentials and execution of commands across numerous cells. Reported victimology also includes government institutions, multinational political bodies, financial institutions, research organizations, and selected individuals involved in advanced mathematics and cryptography.
The initial infection vector has not been established with high confidence. One theory discussed publicly is man-in-the-middle delivery using browser zero-days, but this remains unconfirmed. Regin is best understood as a mature espionage framework optimized for stealth, persistence, internal routing, and long-duration access to strategically significant targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The entries in the log appear to contain Ericsson OSS MML (Man-Machine Language as defined by ITU-T) commands.
Kaspersky products detect modules from the Regin platform as: Trojan.Win32.Regin.gen and Rootkit.Win32.Regin.
the logic branch operation handles routines that issue direct kernel I/O calls (ZwQueryInformationFile, ZwWriteFile, ZwReadFile, ZwClose).
The attackers were able to steal credentials from an internal GSM Base Station Controller belonging to a large telecom operator that gave them access to GSM cells in that particular network.
While in most cases, the attackers were focused on extracting sensitive information, such as e-mails and documents
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
most of the functionality is designed around I/O calls to bridge virtual objects to real files or queries or operate on real file objects
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The machines located on the border of the network act as routers, effectively connecting victims from inside the network with C&Cs on the internet.
The machines located on the border of the network act as routers, effectively connecting victims from inside the network with C&Cs on the internet.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a prior analysis topic and example of an older rootkit/backdoor family, not as a focus of this article.
A sophisticated multi-stage modular espionage implant whose stage 3 kernel component implements a lightweight virtual file system abstraction layer with polymorphic dispatch, direct kernel I/O via Zw* APIs, and IRQL-aware synchronization wrappers for stealthy file-like operations and persistence.
Advanced multi-stage implant family; the content notes 'Regin-class implants' use advanced kernel primitives and VFS-like storage.
An advanced espionage malware referenced only as a comparison point for Daxin’s stealth and communications sophistication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.