Neo-reGeorg is an open-source webshell-based tunneling utility used to turn a compromised web server into a covert pivot point. It is widely deployed in post-exploitation to establish encrypted SOCKS proxy access through externally reachable web applications, allowing operators to route traffic into internal networks and maintain persistent access. Implementations have been observed across common web application stacks, including ASPX, JSP/JSPX, PHP, Go, and ASHX variants, and the tool supports multiplexed TCP connections within a single session.
Operationally, Neo-reGeorg is used after initial compromise rather than as a standalone intrusion vector. Adversaries place the webshell on an internet-facing server or appliance and then use it for proxying, internal access, and command-and-control relay. This makes it useful for lateral movement support, reconnaissance of internal environments, and long-term foothold retention while blending activity into normal web traffic. The tool is frequently paired with other tunneling utilities and reverse proxies as part of layered access architectures.
Neo-reGeorg has been repeatedly observed in espionage and intrusion campaigns conducted by multiple state-linked and advanced threat actors. Reported users include APT41, MuddyWater, Sandworm Team, MURKY PANDA, and the Asia-based espionage cluster tracked as TGR-STA-1030/UNC6619. It has also appeared in financially motivated and hybrid campaigns such as Operation Escaneo, and in intrusions involving exploitation of perimeter devices and email infrastructure. China-nexus operators in particular have been repeatedly associated with Neo-reGeorg webshell deployment on internet-facing appliances and servers.
Target environments include Windows IIS and Java-based web servers as well as Linux-hosted web applications and edge appliances. Victim sectors observed with Neo-reGeorg activity include government, telecommunications, finance, transport, legal, academia, technology, critical infrastructure, and immigration-related services across multiple regions. Because Neo-reGeorg is a publicly available tool rather than a bespoke malware family, its presence is best understood as evidence of post-compromise tunneling, persistence, and internal network pivoting tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
Other infection pathways include exploitation of known security flaws in Citrix NetScaler ADC and NetScaler Gateway (CVE-2023-3519) and Commvault (CVE-2025-3928).
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On some of the compromised Ivanti CSA appliances investigated, webshells related to the open-source tool Neo-reGeorg... were found.
MURKY PANDA has deployed web shells including Neo-reGeorg during their cyberespionage operations... MURKY PANDA heavily relies on exploiting internet-facing appliances to gain initial access and has frequently deployed web shells — including the Neo-reGeorg web shell frequently used by China-nexus adversaries — to establish persistence.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Based on these names, we were able to determine that this instance utilized a Neo-reGeorg web shell tunnel. This tool is used to proxy traffic from an external network to an internal one via an externally accessible web server.
MuddyWater was observed leveraging the Chinese-developed tool Neo-reGeorg to perform webshell-based SOCKS pivoting.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Ensuring persistence, by: – deploying or creating PHP webshells; – modifying existing PHP scripts to add webshells capabilities... On some of the compromised Ivanti CSA appliances investigated, webshells related to the open-source tool Neo-reGeorg or generated via the Behinder (“Ice Scorpion”) webshell framework were found.
AES-encrypted Neo-reGeorg channel key; GZIP-compressed inner payload loaded through reflection with an obfuscated defineClass invocation.
layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels
Multiple SOCKS proxy layers on ports 1080, 1085, 10800, 10843, 10850, 10555, 10830
Layered architecture using a public VPS, SOCKS5 relay at 165.22.184.26, internal pivot and target subnet; per-target proxychains.conf routing.
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
The attackers then started dropping various samples on this server, notably a dropper that was pushing more compiled variants carrying the same functionality... The attackers tried to drop additional post-exploitation tools to achieve their main objectives.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell used to maintain persistence and control within compromised environments, enabling continued attacker access while blending into normal traffic.
A webshell used to establish encrypted footholds on compromised web servers for persistent access.
A webshell/tunneling tool used as part of layered command-and-control infrastructure in Operation Escaneo to support persistence and covert access.
An HTTP-tunneled SOCKS5 webshell framework used for persistence, proxying, internal SMB probing, and command-and-control over AES-encrypted and custom-encoded channels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.