reGeorg is an open-source tunneling web shell used to relay network traffic through a compromised web server, typically by installing a small server-side script on an HTTP application stack such as ASPX, JSP, PHP, or similar platforms. It is commonly used after initial compromise to create HTTP- or SOCKS-based proxy channels that tunnel arbitrary TCP sessions into and out of victim networks, enabling operators to reach otherwise inaccessible internal systems while blending traffic with normal web communications. Documented use includes tunneling of RDP, SSH, and SMB sessions, making it a practical pivoting utility for lateral movement, remote administration, and sustained access.
The tool is widely treated as commodity post-exploitation infrastructure rather than a bespoke implant. It has been observed in intrusions involving exploitation of Microsoft Exchange vulnerabilities, including the 2021 ProxyLogon wave, where attackers deployed reGeorg-style web shells on compromised Exchange and Outlook Web Access servers to maintain access and pivot internally. It has also been associated with APT28 operations, including use on compromised HTTP servers and Exchange environments to maintain persistence and relay traffic for follow-on activity. Reporting has additionally linked variants or deployments of reGeorg to other espionage activity, including operations attributed to LuckyMouse and incidents involving tunnel-capable web shells derived from or similar to reGeorg.
Functionally, reGeorg is best characterized as a web shell with tunneling and proxy capabilities. Its primary value to operators is defense evasion and post-compromise mobility: it hides attacker-controlled communications inside legitimate-looking HTTP or HTTPS flows and can bypass network firewalls and proxy restrictions that would otherwise block direct access to internal services. Because it is deployed on already compromised web infrastructure and used mainly to relay traffic rather than to perform broad autonomous collection or destructive actions, it is most often seen as an enabling component in larger intrusion chains rather than the main payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dans l’un des incidents impliquant le MOA, l’ANSSI a identifié l’exploitation des vulnérabilités CVE-2020-0688 et CVE-2020-17144 à l’encontre d’un serveur Exchange exposé au travers d’une interface Outlook Web Access (OWA). | Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... ReGeorg web shells
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... ReGeorg web shells
rule webshell_aspx_reGeorgTunnel : Webshell Commodity { ... description= "variation on reGeorgtunnel"
Dans l’un des incidents impliquant le MOA, l’ANSSI a identifié l’exploitation des vulnérabilités CVE-2020-0688 et CVE-2020-17144 à l’encontre d’un serveur Exchange exposé au travers d’une interface Outlook Web Access (OWA). | Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
rule webshell_aspx_reGeorgTunnel : Webshell Commodity { ... description= "variation on reGeorgtunnel"
Threat behavior HackTool:JS/ReGeorg is a tunneling tool that uses JavaScript to hide malicious traffic behind the legitimacy of HTTP/HTTPS protocols to get around network firewalls and proxies.
Threat behavior HackTool:JS/ReGeorg is a tunneling tool that uses JavaScript to hide malicious traffic behind the legitimacy of HTTP/HTTPS protocols to get around network firewalls and proxies.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • reGeorg est un outil de création de tunnels exploitant un serveur HTTP compromis sur lequel un script (PHP, ASPX, JSP, etc) spécifique est installé pour relayer du trafic pour d’autres protocoles
ReGeorg — A web shell used to maintain persistent access to a compromised system.
"LuckyMouse... began its attack by dropping the Nbtscan tool, installing a variant of the ReGeorg web shell..."
"One interesting aspect of UNC3524’s use of REGEORG was that it matched identically with the version publicly reported by the NSA as used by APT28."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
ReGeorg typical function begins with some known vulnerabilities like CVE-2021-26084 or CVE-2025-0282 for initial access, usually via a phishing or drive-by download.
Boot or logon initialization scripts, scheduled tasks, valid accounts, manipulating accounts, creating accounts, server software component, create/modify system process, event triggered execution, boot or logon autostart execution, hijack execution flow (MITRE ATT&CK: T1037, T1053, T1078, T1136, T1505, T1543, T1546, T1547, T1574)
L’outil reGeorg a notamment été utilisé pour pérenniser l’accès au serveur [T1505.003].
Another benefit of this technique is that communication occurs over HTTP/S traffic, which may appear legitimate since the compromised server hosts a web service and inbound traffic is expected over these ports.
The second is a component of REGeorg, tunnel.jsp. REGeorg is an open source framework to create socks proxies for communication.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool ... ReGeorg web shells ... Chisel
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commodity webshell and HTTP tunneling tool referenced as an older alternative to suo5 and as historically used in Exchange exploitation.
Named in the IOC appendix as a web shell/tunneling tool associated with the investigated intrusion set artifacts, but not a primary focus of the report narrative.
Named as an example of a reverse proxy tool used by threat actors generally, not specifically tied to the observed intrusion.
Web shell/tunneling utility used to establish covert connectivity (often via HTTP) through a compromised web server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.