reGeorge
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following the initial web shell, a set of both open-source web shells, such as “JspSpy,” “reGeorge,” “MiniWebCmdShell,” “Vonloesch Jsp File Browser 1.2” and custom web shells were uploaded separately or as a bundle and were used by the group.
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Persistence
1 technique
Persistence
The basic payload for these exploits was either a simple obfuscated web shell enabling remote code execution... Following the initial web shell, a set of both open-source web shells, such as “JspSpy,” “reGeorge,” “MiniWebCmdShell,” “Vonloesch Jsp File Browser 1.2” and custom web shells were uploaded separately or as a bundle and were used by the group.
Command and Control
2 techniques
Command and Control
The access to and from the compromised assets are mainly achieved by the group’s web shells and Java tools, both custom and open source, that provide tunneling capabilities of TCP packets and HTTP requests.
Elephant Beetle deploy several tools for tunneling HTTP requests to web shells on internal web servers... One tool the group used was a custom web shell that receives HTTP parameters of a target host port and an encoded HTTP request payload (as a hex-string), creates a connection to the target machine, sends the request and prints the response.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell family referenced in the IOC list, associated with web-tier activity and child-process execution analytics.
Open-source web shell/tunneling tool used to proxy traffic and support internal access and lateral movement.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.