SystemBC Malware Resurges with 10K+ Infections

SystemBC Malware Resurges with 10K+ Infections (TL-2026-0101) is a high-severity malware campaign, first published 2026-02-16. It has no confirmed attribution, maps to 29 MITRE ATT&CK techniques (T1003, T1021, T1021.001), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-0101

Threat ID
TL-2026-0101
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-02-16
Last reviewed
2026-02-16
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
Critical Infrastructure, Healthcare, Financial Services, Government, Manufacturing, Technology, Education
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in SystemBC Malware Resurges with 10K+ Infections

Malware and tooling: SystemBC - S9001, Cobalt Strike, Meterpreter

SystemBC is a multiplatform SOCKS5 proxy backdoor and malware-as-a-service (MaaS) platform active since August 2019, maintaining 80+ C2 servers with a daily average of 1,500 compromised hosts — primarily VPS servers (~80%) — used by a broad coalition of ransomware affiliates (LockBit, Black Basta, Akira, Conti, Ryuk, Nokoyawa, 8Base, Rhysida, BlackSuit, RansomHub) and commercial proxy services (REM Proxy, VN5Socks) for SOCKS5 tunneling, payload delivery, shellcode injection, and network pivoting.

How SystemBC Malware Resurges with 10K+ Infections works

SystemBC is a commoditized proxy backdoor sold in underground forums since at least 2018, with compiled samples dating to July 2017. The platform consists of three components: (1) C2 web server with PHP admin panel, (2) C2 proxy listener managing SOCKS5 tunnels, and (3) backdoor payload available as both EXE and DLL for Windows, plus a Linux variant. Core capabilities include SOCKS5 proxy establishment from victim to C2 (enabling attackers to pivot through victim networks), a loader for downloading and executing files via scheduled tasks (parent process becomes svchost.exe, evading AV correlation), and fileless shellcode injection directly into memory via VirtualProtect + CreateThread (supporting Meterpreter and other frameworks without disk writes). Communication uses a custom RC4-encrypted protocol with XOR encoding using a hardcoded 40-byte key. Lumen Black Lotus Labs (September 2025) documented the botnet's current scale: 80+ C2 servers operated under a single Autonomous System, daily average of 1,500 active bots with ~80% being compromised VPS from five large commercial providers (NOT residential devices — a deliberate choice for bandwidth and longevity). Approximately 40% of infections persist over one month. The botnet feeds into multiple criminal services including REM Proxy (offering ~80% of SystemBC bots plus 20,000 compromised MikroTik routers), Russian web-scraping services, and Vietnamese VN5Socks proxy service. REM Proxy has documented connections to AvosLocker and Morpheus ransomware groups. Europol's Operation Endgame (May 2024) specifically targeted SystemBC alongside IcedID, SmokeLoader, TrickBot, and BumbleBee in the largest-ever botnet takedown. Kaspersky (August 2023) documented DroxiDat, a compact 8KB SystemBC variant, targeting a South African power utility with Cobalt Strike beacons — attributed with low confidence to FIN12/Pistachio Tempest. Kroll (January 2024) provided the definitive C2 server analysis: the PHP panel manages per-victim SOCKS5 ports with optional authentication (RFC 1929), IP-based access control, loader URL submission, and direct shellcode injection with repeat scheduling. SystemBC remains the most widely-adopted ransomware affiliate tunneling tool, providing persistent network access that survives primary C2 remediation. V1 CORRECTION: The '10K+ infections' claim is inflated — Lumen documented 1,500 daily active bots. Cumulative infections over the botnet's 6+ year lifespan would exceed 10K, but daily active count is 1,500.

MITRE ATT&CK techniques used in TL-2026-0101

credential-access

T1003 OS Credential Dumping

lateral-movement

T1021 Remote Services; T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares

defense-evasion

T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070.004 File Deletion

discovery

T1033 System Owner/User Discovery; T1082 System Information Discovery

execution

T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.004 Unix Shell; T1106 Native API

command-and-control

T1071.001 Web Protocols; T1090.002 External Proxy; T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573.001 Symmetric Cryptography; T1573.002 Asymmetric Cryptography

impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

persistence

T1547.001 Registry Run Keys / Startup Folder

resource-development

T1583.005 Botnet; T1584.004 Server

Remediation for SystemBC Malware Resurges with 10K+ Infections

Immediate actions

  • Monitor for SOCKS5 proxy connections on high-numbered ports from internal systems to external C2 infrastructure
  • Block known SystemBC C2 IP ranges (see Lumen IOCs) at firewall and DNS level
  • Hunt for RC4-encrypted traffic on port 443 and port 4000 (default C2 panel port) to suspicious ASNs
  • Check for scheduled tasks with random 19-character lowercase names executing files from %TEMP%
  • Scan for DroxiDat indicators: 8KB executables in C:\perflogs\ registering window class 'Microsoft' with text 'win32app'

Workarounds

  • Block outbound SOCKS5 connections (port 1080 and dynamic high-numbered ports) from non-proxy-authorized systems
  • Monitor and restrict scheduled task creation from processes executing from %TEMP% directory

Longer-term hardening

  • Implement network segmentation to limit SOCKS5 proxy pivoting from compromised hosts
  • Deploy EDR monitoring for VirtualProtect + CreateThread shellcode injection patterns
  • Patch VPS infrastructure — Lumen found victims average 20 unpatched CVEs with at least 1 critical
  • Monitor for registry persistence under Software\Microsoft\Windows\CurrentVersion\Run with 'socks5' entries
  • Deploy Tor exit node and SOCKS5 proxy detection at network perimeter
  • Implement behavioral analysis for outbound SOCKS5 tunneling from enterprise endpoints

Timeline of SystemBC Malware Resurges with 10K+ Infections

  • Earliest known SystemBC executable compiled (July 2017), predating public documentation. Source: Malpedia malware timeline
  • Proofpoint publishes first public documentation of SystemBC: 'Christmas in July for SOCKS5 Malware and Exploit Kits.' Identified as SOCKS5 backconnect proxy distributed via exploit kits (RIG, Fallout). Source: https://www.proofpoint.com/us/threat-insight/post/systembc-christmas-july-socks5-malware-and-exploit-kits
  • Sophos publishes detailed analysis linking SystemBC to multiple ransomware operations: Ryuk, Egregor, and others. Documents automated ransomware deployment capability via SystemBC. Source: https://news.sophos.com/en-us/2020/12/16/systembc/
  • DarkSide ransomware attack on Colonial Pipeline (watershed moment per Kim Zetter, BlackHat 2022). SystemBC identified in DarkSide affiliate toolsets. Source: Kaspersky DroxiDat report referencing DarkSide affiliate infrastructure
  • Kaspersky detects DroxiDat (compact 8KB SystemBC variant) targeting South African power utility alongside Cobalt Strike beacons. Power-utility-themed C2 domains (powersupportplan[.]com, epowersoftware[.]com). Low confidence attribution to FIN12/Pistachio Tempest. Source: https://securelist.com/focus-on-droxidat-systembc/110302/
  • Kroll publishes definitive C2 server analysis: PHP panel with per-victim SOCKS5 ports, RFC 1929 authentication, IP-based access control, loader (file download via scheduled tasks), and fileless shellcode injection (VirtualProtect + CreateThread). Rhysida ransomware confirmed user. Source: https://www.kroll.com/en/insights/publications/cyber/inside-the-systembc-malware-server
  • Europol Operation Endgame — largest-ever botnet takedown targets SystemBC alongside IcedID, SmokeLoader, TrickBot, and BumbleBee dropper ecosystem. Multiple arrests and infrastructure seizures across Europe. Source: https://www.europol.europa.eu/media-press/newsroom/news/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem
  • Mandiant documents UNC4393 (Black Basta primary affiliate cluster) using SystemBC alongside QakBot, Cobalt Strike, and Zloader. SystemBC serves as persistent access layer surviving primary C2 remediation. Source: Mandiant M-Trends 2025 + UNC4393 report
  • DFIR Report documents complete LockBit ransomware attack chain using Cobalt Strike + SystemBC ('Pair of SOCKS'). SystemBC provides SOCKS5 tunneling for lateral movement and exfiltration staging. Source: https://thedfirreport.com/2025/01/27/cobalt-strike-and-a-pair-of-socks-lead-to-lockbit-ransomware/
  • Lumen Black Lotus Labs publishes comprehensive SystemBC botnet analysis: 80+ C2s, 1,500 daily victims (~80% VPS from 5 major providers), 300 GoBrut bots, REM Proxy connection (~80% of SystemBC network), VN5Socks integration, Russian parsing service usage. Single AS hosts all C2s. 40% infection persistence >1 month. Source: https://blog.lumen.com/systembc-bringing-the-noise/
  • ThreadLinqs Intelligence documents SystemBC as the ransomware ecosystem's most widely-adopted affiliate tunneling platform. Verified across 10+ RaaS families. V1 correction: daily active bots = 1,500 (not 10K+). Source: https://intel.threadlinqs.com/#TL-2026-0101
  • As of 2026-05-29, SystemBC remains fully active: it survived Operation Endgame (May 2024) and runs 80+ C2s with 10,000+ infected hosts (Lumen, Silent Push), now adding Linux and Perl variants. April 2026 Check Point/THN reporting ties it to The Gentlemen RaaS with 1,570+ corporate victims; no takedown or successor.

Sources cited for SystemBC Malware Resurges with 10K+ Infections

Threats related to SystemBC Malware Resurges with 10K+ Infections

Detection coverage for TL-2026-0101

As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0101 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats