reGeorg is an open-source HTTP tunneling tool and proxy web shell used to maintain access to compromised web servers and reach internal systems. It combines a SOCKS proxy with a server-side script that relays traffic through a compromised HTTP server. Server-side implementations include PHP, ASPX, and JSP. Its tunnels can carry protocols such as RDP, SSH, and SMB, enabling remote access and lateral movement into networks accessible from the compromised server.
reGeorg is widely used as commodity post-exploitation tooling by espionage actors and ransomware operators. APT28 has deployed modified, obfuscated variants on Outlook Web Access servers to maintain persistence. LuckyMouse installed a variant on a compromised Middle Eastern government email server during the March 2021 Microsoft Exchange exploitation campaign. Red Menshen deployed reGeorg on internet-facing systems to reach internal hosts subsequently infected with BPFDoor. TaskMasters and SamSam operators have also used it for proxying and continued access. Its deployment commonly follows server compromise or exploitation of public-facing applications; it is not itself the vulnerability exploit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
The email subject and the attachment name suggest that a public PoC for ProxyShell exploit was used to gain access to the victims’ network by compromising an exchange server. | “Two types of web shells were used for exploitation: ReGeorg and another open-sourced web shell.”
Dans l’un des incidents impliquant le MOA, l’ANSSI a identifié l’exploitation des vulnérabilités CVE-2020-0688 et CVE-2020-17144 à l’encontre d’un serveur Exchange exposé au travers d’une interface Outlook Web Access (OWA). | Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
Dans l’un des incidents impliquant le MOA, l’ANSSI a identifié l’exploitation des vulnérabilités CVE-2020-0688 et CVE-2020-17144 à l’encontre d’un serveur Exchange exposé au travers d’une interface Outlook Web Access (OWA). | Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
Threat behavior HackTool:JS/ReGeorg is a tunneling tool that uses JavaScript to hide malicious traffic behind the legitimacy of HTTP/HTTPS protocols to get around network firewalls and proxies.
Threat behavior HackTool:JS/ReGeorg is a tunneling tool that uses JavaScript to hide malicious traffic behind the legitimacy of HTTP/HTTPS protocols to get around network firewalls and proxies.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server.
LuckyMouse operators "installed a variant of the ReGeorg webshell" on a compromised government email server.
ReGeorg deployed to internet-facing systems; Access to hosts later infected with BPFDoor
ReGeorg deployed to internet-facing systems; Access to hosts later infected with BPFDoor
“Two types of web shells were used for exploitation: ReGeorg and another open-sourced web shell.”
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Boot or logon initialization scripts, scheduled tasks, valid accounts, manipulating accounts, creating accounts, server software component, create/modify system process, event triggered execution, boot or logon autostart execution, hijack execution flow (MITRE ATT&CK: T1037, T1053, T1078, T1136, T1505, T1543, T1546, T1547, T1574)
Annex B lists Application Layer Protocol: Web Protocols under Command and Control.
The pysoxy YARA rule describes a "SOCKS5 proxy tool used to relay connections," and the ASPX web shell can "act as a Tunnel, using code borrowed from reGeorg."
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool ... ReGeorg web shells ... Chisel
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web-based tunneling tool used to proxy attacker traffic through compromised web servers.
A commodity webshell and HTTP tunneling tool referenced as an older alternative to suo5 and as historically used in Exchange exploitation.
Named in the IOC appendix as a web shell/tunneling tool associated with the investigated intrusion set artifacts, but not a primary focus of the report narrative.
Named as an example of a reverse proxy tool used by threat actors generally, not specifically tied to the observed intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.