ReGeorg is an open-source web-shell-based tunneling tool used after compromise to relay TCP traffic through a compromised HTTP server. Its small server-side components can be implemented in ASPX, PHP, JSP, and related web technologies. An operator connects a client to the deployed web shell to establish an HTTP or SOCKS proxy, enabling tunneled access to internal services such as RDP, SSH, and SMB that may otherwise be inaccessible externally. This makes ReGeorg useful for maintaining access, pivoting into internal networks, and concealing command-and-control or remote-administration traffic within ordinary web communications. ReGeorg has been widely used as commodity post-exploitation tooling, including in Microsoft Exchange compromises and by APT28, which has used modified and obfuscated variants to retain access to compromised Outlook Web Access and Exchange servers. It has also appeared in espionage intrusions affecting government, telecommunications, defense, and other enterprise environments. ReGeorg itself is not an initial-access mechanism; it is typically installed after exploitation of an internet-facing server or other successful compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dans l’un des incidents impliquant le MOA, l’ANSSI a identifié l’exploitation des vulnérabilités CVE-2020-0688 et CVE-2020-17144 à l’encontre d’un serveur Exchange exposé au travers d’une interface Outlook Web Access (OWA). | Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... ReGeorg web shells
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... ReGeorg web shells
rule webshell_aspx_reGeorgTunnel : Webshell Commodity { ... description= "variation on reGeorgtunnel"
Dans l’un des incidents impliquant le MOA, l’ANSSI a identifié l’exploitation des vulnérabilités CVE-2020-0688 et CVE-2020-17144 à l’encontre d’un serveur Exchange exposé au travers d’une interface Outlook Web Access (OWA). | Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
rule webshell_aspx_reGeorgTunnel : Webshell Commodity { ... description= "variation on reGeorgtunnel"
Threat behavior HackTool:JS/ReGeorg is a tunneling tool that uses JavaScript to hide malicious traffic behind the legitimacy of HTTP/HTTPS protocols to get around network firewalls and proxies.
Threat behavior HackTool:JS/ReGeorg is a tunneling tool that uses JavaScript to hide malicious traffic behind the legitimacy of HTTP/HTTPS protocols to get around network firewalls and proxies.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
ReGeorg — A web shell used to maintain persistent access to a compromised system.
"LuckyMouse... began its attack by dropping the Nbtscan tool, installing a variant of the ReGeorg web shell..."
"One interesting aspect of UNC3524’s use of REGEORG was that it matched identically with the version publicly reported by the NSA as used by APT28."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
ReGeorg typical function begins with some known vulnerabilities like CVE-2021-26084 or CVE-2025-0282 for initial access, usually via a phishing or drive-by download.
Boot or logon initialization scripts, scheduled tasks, valid accounts, manipulating accounts, creating accounts, server software component, create/modify system process, event triggered execution, boot or logon autostart execution, hijack execution flow (MITRE ATT&CK: T1037, T1053, T1078, T1136, T1505, T1543, T1546, T1547, T1574)
Godzilla ASPX, r57, suo5... several webshell and tunnel relays running Godzilla ASPX, suo5, r57, reGeorg, and Neo-reGeorg.
Annex B lists Application Layer Protocol: Web Protocols under Command and Control.
The pysoxy YARA rule describes a "SOCKS5 proxy tool used to relay connections," and the ASPX web shell can "act as a Tunnel, using code borrowed from reGeorg."
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool ... ReGeorg web shells ... Chisel
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web-based tunneling tool used to proxy attacker traffic through compromised web servers.
A commodity webshell and HTTP tunneling tool referenced as an older alternative to suo5 and as historically used in Exchange exploitation.
Named in the IOC appendix as a web shell/tunneling tool associated with the investigated intrusion set artifacts, but not a primary focus of the report narrative.
Named as an example of a reverse proxy tool used by threat actors generally, not specifically tied to the observed intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.