Neo-reGeorg is an open-source, dual-use web tunneling toolkit used by attackers as a proxy web shell on compromised servers. It tunnels SOCKS5 traffic over ordinary HTTP or HTTPS connections, allowing operators to reach internal systems through an externally accessible web application. Its server-side components include JSP, JSPX, and ASP.NET implementations. In malicious deployments, it supports post-exploitation access, internal reconnaissance, lateral movement, and data exfiltration through layered proxy infrastructure. Operators have also deployed it over existing web-shell implants and used compromised third-party systems as tunnel relays to obscure their network activity.
ShinyHunters, tracked as UNC6240, has deployed Neo-reGeorg on compromised Oracle PeopleSoft hosts for internal discovery and lateral movement. Shedding Zmiy has deployed an ASP.NET variant through BADSTATE as a virtual web shell residing in IIS worker-process memory without a corresponding file on disk. Neo-reGeorg components have also been incorporated into the GhostContainer backdoor used by NightEagle against Microsoft Exchange servers, and the toolkit formed the basis of the GLASSTOKEN custom web shell. These uses reflect adoption by multiple unrelated operators rather than exclusive attribution to a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the September campaign, attackers also used JSP web shells, the SIDEEYE backdoor, and Neo-reGeorg for tunneling.
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
«...в качестве веб-шелла мы наблюдали файл webshells\tunnel.aspx – файл веб-шелла Neo-reGeorg...»
In the September campaign, attackers also used JSP web shells, the SIDEEYE backdoor, and Neo-reGeorg for tunneling.
GhostContainer is assembled from several open-source components, including the Neo-reGeorg tunnel.
On some of the compromised Ivanti CSA appliances investigated, webshells related to the open-source tool Neo-reGeorg... were found.
MURKY PANDA has deployed web shells including Neo-reGeorg during their cyberespionage operations... MURKY PANDA heavily relies on exploiting internet-facing appliances to gain initial access and has frequently deployed web shells — including the Neo-reGeorg web shell frequently used by China-nexus adversaries — to establish persistence.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
In the September campaign, they also used JSP web shells, the SIDEEYE backdoor, and Neo-ReGeorg for tunneling.
SIDEEYE provides reverse-proxy functionality, and the actor uploaded the Neo-reGeorg tunneling toolkit.
Neo-reGeorg... [was deployed] using third-party compromised systems as reverse tunnels to proxy further malicious actions.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling/proxy kit deployed to facilitate internal discovery and lateral movement from compromised PeopleSoft servers.
A tunneling tool used by the attackers for post-exploitation network access.
A web-shell-based tunneling and proxy tool used to route internal traffic over web connections, facilitating internal discovery and lateral movement following PeopleSoft compromise.
A web-shell-based tunneling/proxy tool used to route internal traffic through ordinary web connections, enabling network discovery and movement beyond the initially compromised PeopleSoft host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.