SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscation
SystemBC (Coroxy) Malware (TL-2026-1005), also tracked as Coroxy, is a critical-severity malware campaign, first published 2026-06-30. It is attributed to Egregor with high confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1001, T1053, T1057), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1005
- Threat ID
- TL-2026-1005
- Also known as
- Coroxy, DroxiDat, SYSTEMBC RAT, Socks5 Proxy Backdoor, S9001
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-30
- Last reviewed
- 2026-06-30
- Attribution
- Egregor
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- hosting-providers, critical-infrastructure, government administration, finance, technology
- Target regions
- North America, Europe, 143 - Central Asia, Latin America, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in SystemBC (Coroxy) Malware
Malware and tooling: Embedded Tor library (mini-tor)
SystemBC is a Windows backdoor malware actively deployed by six major ransomware families (Ryuk, Egregor, Conti, BlackBasta, Play, Rhysida, Cactus) to establish persistent remote access and hide command-and-control traffic using embedded Tor gateway infrastructure. The malware converts compromised systems into SOCKS5 proxies, enabling attackers to route external traffic through internal networks and deploy secondary payloads including post-exploitation frameworks and encryption malware.
How SystemBC (Coroxy) Malware works
SystemBC, also known as Coroxy or DroxiDat, is a sophisticated Windows remote access trojan (RAT) that serves as a critical tool in the ransomware supply chain. First discovered in 2019 and actively deployed since 2020, SystemBC provides ransomware operators with reliable persistent backdoor access and C2 infrastructure obfuscation capabilities. The malware utilizes a multi-stage deployment process, typically delivered via email-based phishing campaigns or loader malware (Buer, Qbot, Zloader, Bazar, Emotet, Matanbuchus 3.0). Upon execution, SystemBC establishes persistence through dual mechanisms: Windows registry Run keys and scheduled tasks with random naming patterns. The malware communicates with command-and-control servers using RC4-encrypted custom binary protocols, with modern variants leveraging embedded Tor libraries to route communications through the Tor network, making detection and attribution significantly more difficult. A key feature is its ability to execute payloads directly in memory without writing to disk, bypassing many disk-based detection systems and forensic analysis. SystemBC converts infected systems into SOCKS5 proxy servers, allowing remote attackers to tunnel traffic through internal networks and access resources that would otherwise be unreachable from external networks. This proxy functionality is particularly valuable for ransomware operations, enabling lateral movement through network segments and deployment of attack frameworks like Cobalt Strike. The malware's system reconnaissance capabilities collect Windows usernames, build numbers, device names, architecture information, and volume serial numbers—intelligence used for targeting decisions and attack planning. As of February 2026, security researchers have identified over 10,000 actively infected systems worldwide, with the majority hosted on bullet-proof hosting providers. The infrastructure targeting pattern suggests SystemBC operators deliberately focus on hosting providers and critical infrastructure, likely to establish a supply of proxy infrastructure that can be rented or sold to other criminal groups. The malware has demonstrated continuous evolution, with new variants discovered regularly including PowerShell-based versions and previously undocumented Perl variants targeting Linux systems.
MITRE ATT&CK techniques used in TL-2026-1005
command-and-control
Persistence
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1124 System Time Discovery
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel
discovery
Defense Evasion
T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1564 Hide Artifacts; T1620 Reflective Code Loading; T1678 Delay Execution
Affected products and versions in SystemBC (Coroxy) Malware
- Microsoft — Windows
Vulnerable versions: 7; 8; 10; 11; Server 2012; Server 2016; Server 2019; Server 2022
Remediation for SystemBC (Coroxy) Malware
Patches
- Apply latest Windows security updates and address all known critical vulnerabilities exploited by loaders (Buer, Qbot, Zloader)
Immediate actions
- Identify and terminate all SystemBC processes by checking %ProgramData% and scheduled tasks with random names
- Block identified C2 infrastructure (193.106.191.168, 188.127.224.46, 45.10.42.221) at perimeter firewalls
- Audit Windows registry for unauthorized Run key entries (HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run)
- Scan all systems for registry persistence artifacts and scheduled tasks in C:\\Windows\\Tasks\\
- Monitor network egress for Tor bootstrap connections and RC4-encrypted traffic on port 4044
- Isolate infected systems from network until verified clean via disk imaging
- Reset credentials for all domain administrators and high-privilege accounts
- Review all lateral movement indicators, focusing on Cobalt Strike beacon activity
Workarounds
- Disable PowerShell execution via Group Policy if not required for operations
- Restrict scheduled task creation to administrative accounts only
- Implement AppLocker rules preventing execution from %ProgramData% for non-system processes
- Block common loader execution paths (temporary internet folders, downloads)
Longer-term hardening
- Deploy behavioral endpoint detection (EDR) focusing on in-memory code execution, ProcessCreate with hidden windows, and SOCKS5 proxy establishment
- Implement DNS sinkholing for known C2 domains and .bit domain queries indicating Tor usage
- Deploy Splunk/KQL rules detecting registry modifications to Run keys with suspicious encoded PowerShell commands
- Enable Windows Defender Application Guard and Application Control (WDAC) to restrict execution contexts
- Conduct network segmentation to prevent compromised systems from pivoting to critical infrastructure
- Implement proxy-level controls blocking Tor exit node traffic and non-standard port 4044 communications
- Deploy threat intelligence feeds for bulletproof hosting provider AS numbers (AS213790, AS19871, AS22612, AS46606) and auto-block suspicious ingress
- Establish incident response procedures for ransomware supply chain attacks identifying SystemBC as early warning
Weaknesses (CWE) in SystemBC (Coroxy) Malware
CWE-502, CWE-656, CWE-78
Timeline of SystemBC (Coroxy) Malware
- SystemBC first advertised in underground malware marketplace
- Proofpoint researchers publicly discover SystemBC being distributed via Fallout exploit kit
- SystemBC distributed via RIG exploit kit using Amadey loader as vector; widespread initial compromise phase begins
- Major ransomware groups Ryuk and Egregor adopt SystemBC as primary persistence and C2 obfuscation tool; hundreds of deployments documented
- BlackBerry Threat Intelligence published comprehensive analysis of SystemBC capabilities and ransomware supply chain role
- Over 56,000 unique infected IP addresses tracked globally since malware emergence; infrastructure scale becomes apparent
- Kaspersky publishes detailed analysis of DroxiDat/SystemBC variants and MITRE ATT&CK mapping
- Conti ransomware group continues large-scale deployment of SystemBC; CISA issues advisory on Black Basta linked to SystemBC infrastructure
- Black Basta operators launch social engineering campaigns using fake IT support calls to deliver SystemBC backdoor
- Microsoft Teams-based social engineering campaign distributing SystemBC identified; threat actors impersonate organization IT departments
- Black Basta internal communications leaked, exposing SystemBC deployment logs from September 2023 through September 2024
- Trend Micro reports Black Basta and Cactus ransomware groups combining BackConnect malware with SystemBC for enhanced infrastructure access
- Silent Push identifies over 10,000 actively infected systems worldwide; predominantly hosted on bulletproof hosting providers
- Matanbuchus 3.0 loader discovered delivering SystemBC backdoor alongside Astarion RAT in coordinated attack campaigns
- C2 infrastructure analysis exposes 1,570+ victims in connection with Gentlemen ransomware operation using SystemBC proxy infrastructure
Sources cited for SystemBC (Coroxy) Malware
- SystemBC Malware: How the Coroxy Proxy Backdoor Targets Windows
- Silent Push: SystemBC Identifies More Than 10,000 Infected IPs
- Bitsight: SystemBC - The Multipurpose Proxy Bot Still Breathes
- Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor - Sophos
- Proofpoint: SystemBC - Christmas in July with SOCKS5 Malware and Exploit Kits
- Threat Thursday: SystemBC – a RAT in the Pipeline - BlackBerry
- SophosLabs IOCs Repository - SystemBC
- MITRE ATT&CK: SystemBC (S9001)
- Kroll: Inside The SYSTEMBC Malware Server
- Trend Micro: Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
- Kaspersky Securelist: Focus on DroxiDat/SystemBC
- WithSecure Labs: Prelude to Ransomware: SystemBC
- Black Basta-Linked Attackers Target Users with SystemBC Malware
- CISA #StopRansomware: Black Basta Advisory
- Huntress: A New RAT and a Hands-on-Keyboard Intrusion
Threats related to SystemBC (Coroxy) Malware
- SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operations
- Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing Campaign
- TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industry
- PureCrypter — C# Malware-as-a-Service Loader Distributing 10+ Malware Families
Detection coverage for TL-2026-1005
As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1005 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.