Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 7 hostnames
SystemBC is a Windows malware family best known as a SOCKS5 backconnect proxy and remote access tool that has evolved from a covert communications utility into a multifunctional malware-as-a-service platform used extensively in crimeware and ransomware operations.
Profile source: Mallory opens in a new tabSYSTEMBC
SystemBC is a Windows malware family best known as a SOCKS5 backconnect proxy and remote access tool that has evolved from a covert communications utility into a multifunctional malware-as-a-service platform used extensively in crimeware and ransomware operations. Early variants primarily provided TLS-encrypted proxying to relay malicious traffic and conceal operator activity, while later variants added command execution and payload delivery capabilities, including the ability to run scripts and additional executables or DLLs on compromised hosts. SystemBC is commonly used to maintain persistent access, tunnel RDP and other traffic into victim networks, and support hands-on-keyboard post-compromise activity.
SystemBC has been observed in enterprise intrusions associated with ransomware affiliates and broader big-game-hunting tradecraft, including incidents involving PLAY ransomware and other financially motivated actors. It has also appeared in long-running espionage-oriented intrusions, including activity attributed to Iranian operators targeting Middle Eastern critical infrastructure, where it was used alongside tunneling tools, web shells, credential theft tooling, and lateral movement utilities. In criminal ecosystems, SystemBC has been delivered by other malware families and access brokers, including BatLoader, Emotet, and Gootloader-derived intrusion chains, underscoring its role as a modular follow-on payload rather than a primary initial infection mechanism in many cases.
The malware is strongly associated with stealthy communications. Multiple reports describe its use of TLS to blend command-and-control and proxy traffic into normal encrypted network activity, sometimes over non-standard ports. PowerShell-based variants implement SOCKS-style proxying through background jobs and have been used to establish tunnels that expose internal systems to external operator access. Native variants have been observed creating scheduled tasks or autorun-based persistence and using hidden PowerShell execution or DLL sideloading-style loader chains to reduce visibility. Some samples are heavily packed, including with VMProtect and additional custom packing layers, reflecting a sustained emphasis on anti-analysis and defense evasion.
Operationally, SystemBC is most often used after initial compromise to provide persistence, covert access, and traffic forwarding for subsequent actions such as credential theft, lateral movement, remote administration, and ransomware staging. It has been used to proxy RDP into internal environments, support compromise of domain controllers and backup infrastructure, and facilitate broader post-exploitation workflows. Its prevalence across ransomware, loader, and intrusion-service ecosystems has made SystemBC a durable and widely recognized component of modern Windows intrusion chains.
C2 tracking
Derp observations, rolling seven-day window
Samples
047e138efd0c8dbb52cc949ad66ffc45f4a64eeecd7d35fc2fa473495785fb1a 5760bf3dfa834dd40a2d43d948d7bb617014f6fd324bd8be6701e91f9176921f 6acc0714d3cbab8c42b03d03044f0c56134ed9a651bd1f7a88d8c8f56c978f6a 8684751f02d87ad7979218ee32929bd7d1dbad5f22dd78016f4d9d9144662ece 94ef48cdfeaf9733cab63ef0b640c506856ed636da5c6760ed6727a005657b19 0fad6e315ac98a53a9f5e389ce4e96260c5a7c731a0caef82e14d8784d984f81 20050cc746d46eca3f9611d4ae82314980d17429143aa38c1527303f9f492162 2191775719838df28ac99833767f10d7e44d1273acade8e64b0be1200539a076 6caf984c9d892bce1e99da164d2a6714de11f560aac487b47dc69c9013129f47 78d1caf6c50b8589ffaca75d22ff111e46aabaa3ea9e6be19906735f5703ab62 Reported operators
C:\windows\en-us\ClMgr.dll ... ClMgr.dll ... SystemBC | In this intrusion, this DarkLoadLibrary variant was used to load âClMgr.dllâ which FortiGuard identified as a SystemBC agent.
We also expose how it historically used SystemBC to manage the proxies located in Ukraine to avoid blocklists that would launch the malspam campaigns.
We also expose how it historically used SystemBC to manage the proxies located in Ukraine to avoid blocklists that would launch the malspam campaigns.
Batloader can install different malware families, such as: Bumble Loader Cobalt Strike Qakbot Raccoon Stealer RedLine Stealer Smoke Loader System BC Ursnif (Bot) Vidar (Stealer) ZLoader
Proofpoint saw [TA577] involved in the distribution of payloads such as QakBot, IcedID, SystemBC as well as Cobalt Strike.
SystemBC has historically been a proxy bot that has been around for sale since at least April 2019... The malware itself is pretty simplistic, although effective, but has mostly evolved into both a backdoor and proxy bot since it was first released.
Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.
Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.
Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
they executed a PowerShell command to download additional payloads from a remote location using a Cobalt Strike Beacon, maintaining persistence throughout this process using SystemBC.
SystemBC is primarily used as a SOCKS5 proxy allowing for interaction between victim machines and attacker infrastructure to execute commands, deploy additional payloads or exfiltrate data... 8base uses SystemBC to encrypt command and control traffic...
SYSTEMBC is a tunneler written in C that retrieves proxy-related commands from a command-and-control (C2 or C&C) server using a custom binary protocol over TCP. A C2 server directs SYSTEMBC to act as a proxy between the C2 server and a remote system.
Its affiliates are increasingly leveraging SystemBC malware, a proxy and backdoor tool often used in human-operated ransomware attacks, to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments.
Vice Society actors have been observed using a variety of tools, including SystemBC, PowerShell Empire, and Cobalt Strike to move laterally.
Les attaquants ont utilisĂ© leur accĂšs de bureau Ă distance afin dâexĂ©cuter deux portes dĂ©robĂ©es : SystemBC et Cobalt Strike.
The campaign, internally dubbed "FortiSync Quasar," revealed an evolution from ransomware operations to strategic espionage, deploying Matanbuchus 3.0, Astarion RAT, and SystemBC.
Attackers leverage credential theft, lateral movement tools (Cobalt Strike, SystemBC), and social engineering (notably by UNC3944/Scattered Spider) to escalate privileges and deploy Linux-based ESXi encryptors.
"Additional Resources ... SystemBC"; "Exfiltration Over C2 Channel (performed by SystemBC and Rclone)"
"...installed persistence mechanisms using custom tools and a SystemBC implant."
Arctic Wolf has spotted a financially motivated group named Greedy Sponge target organizations in Mexico with malspam that delivers versions of AllaKore RAT and SystemBC.
"Next, the SystemBC malicious proxy was deployed on the domain controller. SystemBC is a SOCKS5 proxy used to conceal malware traffic..."
"First seen in 2019, SystemBC is a proxy and remote administrative tool... favored by actors behind high-profile ransomware campaigns."
SYSTEMBC is a proxy malware that beacons to its C2 and opens new proxy connections between the C2 and remote hosts as indicated by the C2.
SystemBC is a socks5 backdoor with the ability to communicate over TOR.
X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware, with several dynamic subclusters sharing crypters, malware frameworks, and ransomware variants.
Exploited software
MITRE ATT&CK
Reporting
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.
Attackers operating the Gootkit loader compromised legitimate websites and used SEO poisoning to lure users searching for legal document templates into downloading malicious ZIP archives. The archives contained JavaScript that, once executed, launched obfuscated PowerShell and began a multi-stage infection chain designed to avoid writing the final payload to disk. Trend Micro reported that the updated intrusion flow used registry stuffing, scheduled-task persistence, and reflective in-memory loading to reconstruct and run a fileless Cobalt Strike beacon. The campaign differed from earlier Gootkit activity by shifting from freeware-themed lures to legal-document themes and by encrypting registry-stored content with a custom text-replacement algorithm instead of Base64; in the observed case, the beacon communicated with 89.238.185.13 before the attack was interrupted.
Researchers documented targeted intrusion campaigns that used military and geopolitical decoy documents to compromise victims in South Asia and deploy Cobalt Strike. Cisco Talos reported that attackers distributed malicious Microsoft Office files posing as Indian Air Force and other government or military documents, with macros dropping a custom loader called IndigoDrop into the Windows Startup folder for persistence. IndigoDrop performed anti-infection checks, fetched Metasploit shellcode, and ultimately loaded an XOR-encoded Cobalt Strike beacon hidden in trojanized jQuery files, while related Python modules conducted reconnaissance and stole browser and Wi-Fi credentials. A separate campaign analyzed by Zscaler used a Word document themed around the India-China border dispute to trigger a macro-delivered PowerShell chain that staged shellcode behind a fake GIF header and installed a Cobalt Strike beacon over HTTPS. The operators used fileless techniques, spoofed HTTP Host headers such as update.windows.microsoft.com, and in some variants injected an RSA-encrypted payload into notepad.exe; researchers also identified infrastructure including 47.240.73.77, 114.67.110.37, and 360doc.com-based command-and-control domains. Across both campaigns, the attackers relied on topical military lures, multi-stage loaders, and legitimate-looking web traffic to conceal remote access activity against likely government and defense-related targets.
Researchers linked Batloader activity to the Water Minyades / DEV-0569 / SteelClover ecosystem, which used malvertising, SEO poisoning, and fake software download pages to lure victims into installing trojanized packages. The campaigns abused legitimate installer frameworks such as Advanced Installer and WiX, then shifted to obfuscated JavaScript and PyArmor-protected Python loaders that fingerprinted hosts, contacted command-and-control infrastructure, escalated privileges, and attempted to disable security tools. Operators also used cloned software sites and malicious Google ads to distribute MSI files that launched PowerShell, added Microsoft Defender exclusions, and retrieved encrypted follow-on payloads. The infections were used to selectively deploy a broad set of malware, including Qakbot, Ursnif, Vidar, ZLoader, RedLine Stealer, Raccoon Stealer, Cobalt Strike, and remote-management tools such as Atera and Syncro. Trend Micro reported that Batloader infections observed from September 2022 onward were associated with Royal ransomware, while NTT documented a surge of related infections at Japanese companies in early 2023 through the FakeGPG and BatApp campaigns. The activity was concentrated heavily in the United States but also affected Canada, Germany, Japan, and the United Kingdom, underscoring Batloader's role as a flexible initial-access platform for both credential theft and ransomware intrusion chains.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.