ATT&CKSoftwareNeo-reGeorg

Neo-reGeorg

S1189

Malware.View on attack.mitre.org

About this malware

Neo-reGeorg is an open-source web shell designed as a restructuring of reGeorg with improved usability, security, and fixes for exising reGeorg bugs.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1059.006
Python

Neo-reGeorg is a Python-based web shell.

T1071.001
Web Protocols

Neo-reGeorg can use customized HTTP headers.

T1090
Proxy

Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server.

T1095
Non-Application Layer Protocol

Neo-reGeorg can create multiple TCP connections for a single session.

T1105
Ingress Tool Transfer

Neo-reGeorg has the ability to download files to targeted systems.

T1132.002
Non-Standard Encoding

Neo-reGeorg can use modified Base64 encoding to obfuscate communications.

T1505.003
Web Shell

Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections.

T1572
Protocol Tunneling

Neo-reGeorg can tunnel data in and out of targeted networks.

Groups that use it1

Campaigns0

None recorded.

References1

  1. GitHub Neo-reGeorg 2019 Open source
    L-Codes. (2019). Neo-reGeorg. Retrieved December 4, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.