REGEORG.NEO is a publicly available PHP web shell/tunneling tool, described as an improvement to the REGEORG project, that is used to establish a SOCKS proxy on a compromised system for network tunneling and pivoting. The provided content places it in the web shell category and specifically identifies it as a PHP tunnel. Mandiant observed a REGEORG.NEO variant deployed as config.php on compromised Citrix NetScaler ADC/Gateway appliances during exploitation associated with CVE-2023-3519; in that activity, it was one of six web shells found under /var/vpn/themes and was used alongside other post-exploitation tooling including SECRETSAUCE web shells, a persistent tunneler named "the," and NPS tunneler software (npc). CERT-UA also reported pre-created PHP webshell/tunneling tools including REGEORG.NEO on vendor software servers compromised during Sandworm/UAC-0133 intrusions targeting Ukrainian critical infrastructure organizations in the energy, water, and heat sectors, where those servers were used for lateral movement into corporate networks. High-confidence behavior directly supported by the content is that REGEORG.NEO functions as a web shell-based SOCKS proxy/tunnel for post-compromise access and internal pivoting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One of the vulnerabilities, CVE-2023-3519, could allow an unauthenticated remote attacker to perform arbitrary code execution... Citrix has stated that they have observed exploitation of this vulnerability in the wild... While this vulnerability has been exploited in the wild, the exploit code is not yet publicly available.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.