Also known as: Prax, WarriorPride, QUERTY
Executive Summary
Regin represents a highly modular Windows backdoor that has been active for over a decade, used by state‑sponsored actors to infiltrate telecom, financial, and government targets. It provides stealthy remote control while using encrypted C&C channels to evade detection. Security teams should prioritize advanced host monitoring and network traffic analysis to mitigate its persistence mechanisms.
Enhanced Description
Regin is a sophisticated Windows-based malware platform first identified in the early 2000s but still active in recent years. It operates as a modular remote access trojan, allowing operators to add or remove capabilities such as keylogging, credential harvesting, screen capture, and file exfiltration on demand. The code base includes custom encryption routines for both payload delivery and command‑and‑control traffic, which is typically tunneled over standard HTTPS or a custom protocol that mimics legitimate traffic. Operationally Regin demonstrates characteristics of a highly curated supply chain targeting critical infrastructure and high‑value government entities across multiple continents. In addition to basic remote control functions it can modify the Windows registry and create services for persistence, enabling long‑term access even after system reboots. The modularity of the platform means new modules are routinely uploaded from authoritative servers that are themselves obfuscated and frequently changed to evade signature detection. The threat actor behind Regin is widely attributed to a state-sponsored group (often called Group 14 or APT42). Security researchers have linked its activity to coordinated campaigns against telecom operators, financial institutions, and public‑sector research labs. The persistence of the platform over more than a decade underscores the operational tempo and resources invested by the actor. From an impact perspective Regin can steal banking credentials, exfiltrate proprietary data, and provide persistent footholds for further lateral movement. Its use of encrypted telemetry makes it difficult to detect with conventional signature‑based solutions; however, many mitigations remain effective if applied in combination with host and network visibility controls.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available intelligence from leading cybersecurity vendors, which provides a high level of confidence regarding Regin’s capabilities and use-cases. However, details about the full range of modules, precise command‑and‑control infrastructure, and ongoing operational tactics are not fully disclosed, leaving some gaps in granular threat profiling.
Regin is a malware platform that has targeted victims in a range of industries, including telecom, government, and financial institutions. Some Regin timestamps date back to 2003. (Citation: Kaspersky Regin)