Neo Regeorg

Malware updated a month ago (2024-11-29T14:32:54.093Z)
Download STIX
Preview STIX
Neo-reGeorg is a type of malware that was first observed in use by the Sandworm APT group in June 2022. The initial attack vector remains unknown, but researchers noted that the group's activity began with the deployment of the Neo-REGEORG webshell on a server exposed to the public internet. This harmful program, designed to exploit and damage computer systems, can infiltrate through suspicious downloads, emails, or websites without the user's knowledge. Once inside, it can steal personal information, disrupt operations, or even hold data hostage for ransom. The hackers used reGeorg or Neo-reGeorg to set up a proxy to tunnel network traffic after compromising a victim website. This allowed them to maintain access to the compromised systems and further their illicit activities undetected. Furthermore, they utilized ProxyChains to run Nmap within the network, an action that enables scanning and exploration of the victim's network infrastructure to identify potential vulnerabilities and additional targets. At the time of initial access, Russian hackers deployed a web shell known as neo-regeorg on an internet-facing server. This activity aligns with the group's previous behavior of scanning and exploiting internet-facing servers for initial access. Following this, they deployed GoGetter, a custom TCP tunneling tool, for command and control. This tool allows the attackers to maintain a persistent presence within the compromised system, execute commands remotely, and exfiltrate data, demonstrating a sophisticated level of cyber espionage capability.
Description last updated: 2024-11-21T10:46:15.989Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Webshell
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Neo Regeorg Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more