Skip to content

SYSTEMBC

SystemBC is a Windows malware family best known as a SOCKS5 backconnect proxy and remote access tool that has evolved from a covert communications utility into a multifunctional malware-as-a-service platform used extensively in crimeware and ransomware operations.

Profile source: Mallory opens in a new tab

SYSTEMBC

Family profile

SystemBC is a Windows malware family best known as a SOCKS5 backconnect proxy and remote access tool that has evolved from a covert communications utility into a multifunctional malware-as-a-service platform used extensively in crimeware and ransomware operations. Early variants primarily provided TLS-encrypted proxying to relay malicious traffic and conceal operator activity, while later variants added command execution and payload delivery capabilities, including the ability to run scripts and additional executables or DLLs on compromised hosts. SystemBC is commonly used to maintain persistent access, tunnel RDP and other traffic into victim networks, and support hands-on-keyboard post-compromise activity.

SystemBC has been observed in enterprise intrusions associated with ransomware affiliates and broader big-game-hunting tradecraft, including incidents involving PLAY ransomware and other financially motivated actors. It has also appeared in long-running espionage-oriented intrusions, including activity attributed to Iranian operators targeting Middle Eastern critical infrastructure, where it was used alongside tunneling tools, web shells, credential theft tooling, and lateral movement utilities. In criminal ecosystems, SystemBC has been delivered by other malware families and access brokers, including BatLoader, Emotet, and Gootloader-derived intrusion chains, underscoring its role as a modular follow-on payload rather than a primary initial infection mechanism in many cases.

The malware is strongly associated with stealthy communications. Multiple reports describe its use of TLS to blend command-and-control and proxy traffic into normal encrypted network activity, sometimes over non-standard ports. PowerShell-based variants implement SOCKS-style proxying through background jobs and have been used to establish tunnels that expose internal systems to external operator access. Native variants have been observed creating scheduled tasks or autorun-based persistence and using hidden PowerShell execution or DLL sideloading-style loader chains to reduce visibility. Some samples are heavily packed, including with VMProtect and additional custom packing layers, reflecting a sustained emphasis on anti-analysis and defense evasion.

Operationally, SystemBC is most often used after initial compromise to provide persistence, covert access, and traffic forwarding for subsequent actions such as credential theft, lateral movement, remote administration, and ransomware staging. It has been used to proxy RDP into internal environments, support compromise of domain controllers and backup infrastructure, and facilitate broader post-exploitation workflows. Its prevalence across ransomware, loader, and intrusion-service ecosystems has made SystemBC a durable and widely recognized component of modern Windows intrusion chains.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
0 IP / 7 hostnames

Leading locations

  • US7

Leading providers

  • Google LLC6
  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 7

Samples

Recent associated samples

Reported operators

Threat actors

30 named in public reporting
Fox Kitten

C:\windows\en-us\ClMgr.dll ... ClMgr.dll ... SystemBC | In this intrusion, this DarkLoadLibrary variant was used to load ‘ClMgr.dll’ which FortiGuard identified as a SystemBC agent.

UAC-0006

We also expose how it historically used SystemBC to manage the proxies located in Ukraine to avoid blocklists that would launch the malspam campaigns.

UAC-0050

We also expose how it historically used SystemBC to manage the proxies located in Ukraine to avoid blocklists that would launch the malspam campaigns.

Water Minyades

Batloader can install different malware families, such as: Bumble Loader Cobalt Strike Qakbot Raccoon Stealer RedLine Stealer Smoke Loader System BC Ursnif (Bot) Vidar (Stealer) ZLoader

TA577

Proofpoint saw [TA577] involved in the distribution of payloads such as QakBot, IcedID, SystemBC as well as Cobalt Strike.

Trickbot

SystemBC has historically been a proxy bot that has been around for sale since at least April 2019... The malware itself is pretty simplistic, although effective, but has mostly evolved into both a backdoor and proxy bot since it was first released.

Storm-1811

Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.

Blitz Brigantine

Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.

STAC5777

Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.

WIZARD SPIDER

SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.

RomCom

SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.

Gold Dupont

SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.

Maze

SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.

RIDDLE SPIDER

SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.

DragonForce

they executed a PowerShell command to download additional payloads from a remote location using a Cobalt Strike Beacon, maintaining persistence throughout this process using SystemBC.

8Base

SystemBC is primarily used as a SOCKS5 proxy allowing for interaction between victim machines and attacker infrastructure to execute commands, deploy additional payloads or exfiltrate data... 8base uses SystemBC to encrypt command and control traffic...

UNC4393

SYSTEMBC is a tunneler written in C that retrieves proxy-related commands from a command-and-control (C2 or C&C) server using a custom binary protocol over TCP. A C2 server directs SYSTEMBC to act as a proxy between the C2 server and a remote system.

TheGentlemen

Its affiliates are increasingly leveraging SystemBC malware, a proxy and backdoor tool often used in human-operated ransomware attacks, to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments.

Vanilla Tempest

Vice Society actors have been observed using a variety of tools, including SystemBC, PowerShell Empire, and Cobalt Strike to move laterally.

PISTACHE TEMPEST

Les attaquants ont utilisĂ© leur accĂšs de bureau Ă  distance afin d’exĂ©cuter deux portes dĂ©robĂ©es : SystemBC et Cobalt Strike.

Mora_001

The campaign, internally dubbed "FortiSync Quasar," revealed an evolution from ransomware operations to strategic espionage, deploying Matanbuchus 3.0, Astarion RAT, and SystemBC.

Scattered Spider

Attackers leverage credential theft, lateral movement tools (Cobalt Strike, SystemBC), and social engineering (notably by UNC3944/Scattered Spider) to escalate privileges and deploy Linux-based ESXi encryptors.

Black Basta

"Additional Resources ... SystemBC"; "Exfiltration Over C2 Channel (performed by SystemBC and Rclone)"

Storm-0506

"...installed persistence mechanisms using custom tools and a SystemBC implant."

Greedy Sponge

Arctic Wolf has spotted a financially motivated group named Greedy Sponge target organizations in Mexico with malspam that delivers versions of AllaKore RAT and SystemBC.

Ryuk

"Next, the SystemBC malicious proxy was deployed on the domain controller. SystemBC is a SOCKS5 proxy used to conceal malware traffic..."

TAC5279

"First seen in 2019, SystemBC is a proxy and remote administrative tool... favored by actors behind high-profile ransomware campaigns."

UNC2198

SYSTEMBC is a proxy malware that beacons to its C2 and opens new proxy connections between the C2 and remote hosts as indicated by the C2.

REF9019

SystemBC is a socks5 backdoor with the ability to communicate over TOR.

Hive0163

X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware, with several dynamic subclusters sharing crypters, malware frameworks, and ransomware variants.

Exploited software

Vulnerabilities linked to SYSTEMBC

6 CVEs

MITRE ATT&CK

SYSTEMBC in ATT&CK

71 distinct techniques

Techniques

71 techniques
T1564.003 Hidden Window T1021 Remote Services T1572 Protocol Tunneling T1573 Encrypted Channel T1102 Web Service T1090.003 Multi-hop Proxy T1105 Ingress Tool Transfer T1622 Debugger Evasion T1090 Proxy T1027 Obfuscated Files or Information T1497.001 System Checks T1553 Subvert Trust Controls T1095 Non-Application Layer Protocol T1053.005 Scheduled Task T1547.001 Registry Run Keys / Startup Folder T1021.001 Remote Desktop Protocol T1059.001 PowerShell T1112 Modify Registry T1055.002 Portable Executable Injection T1071 Application Layer Protocol T1090.001 Internal Proxy T1587.001 Malware T1140 Deobfuscate/Decode Files or Information T1129 Shared Modules T1204.002 Malicious File T1053 Scheduled Task/Job T1070.004 File Deletion T1071.001 Web Protocols T1569.002 Service Execution T1204 User Execution T1566.001 Spearphishing Attachment T1090.002 External Proxy T1059.003 Windows Command Shell T1566 Phishing T1059.005 Visual Basic T1059 Command and Scripting Interpreter T1041 Exfiltration Over C2 Channel T1570 Lateral Tool Transfer T1082 System Information Discovery T1219 Remote Access Tools T1057 Process Discovery T1620 Reflective Code Loading T1567 Exfiltration Over Web Service T1036 Masquerading T1190 Exploit Public-Facing Application T1078.002 Domain Accounts T1021.002 SMB/Windows Admin Shares T1608.001 Upload Malware T1562 Impair Defenses T1021.004 SSH T1133 External Remote Services T1078 Valid Accounts T1553.002 Code Signing T1027.002 Software Packing T1047 Windows Management Instrumentation T1074 Data Staged T1583 Acquire Infrastructure T1588.001 Malware T1132.002 Non-Standard Encoding T1583.004 Server T1036.005 Match Legitimate Resource Name or Location T1055 Process Injection T1486 Data Encrypted for Impact T1071.004 DNS T1588.002 Tool T1571 Non-Standard Port T1573.001 Symmetric Cryptography T1583.001 Domains T1189 Drive-by Compromise T1218 System Binary Proxy Execution T1566.003 Spearphishing via Service

Reporting

Research mentioning SYSTEMBC

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

Jan 1
Sophos Threat Research

“Gootloader” expands its payload delivery options | SOPHOS

Attackers operating the Gootkit loader compromised legitimate websites and used SEO poisoning to lure users searching for legal document templates into downloading malicious ZIP archives. The archives contained JavaScript that, once executed, launched obfuscated PowerShell and began a multi-stage infection chain designed to avoid writing the final payload to disk. Trend Micro reported that the updated intrusion flow used registry stuffing, scheduled-task persistence, and reflective in-memory loading to reconstruct and run a fileless Cobalt Strike beacon. The campaign differed from earlier Gootkit activity by shifting from freeware-themed lures to legal-document themes and by encrypting registry-stored content with a custom text-replacement algorithm instead of Base64; in the observed case, the beacon communicated with 89.238.185.13 before the attack was interrupted.

Jan 1
Zscaler Com Other

Targeted Attack Leverages India-China Border Dispute

Researchers documented targeted intrusion campaigns that used military and geopolitical decoy documents to compromise victims in South Asia and deploy Cobalt Strike. Cisco Talos reported that attackers distributed malicious Microsoft Office files posing as Indian Air Force and other government or military documents, with macros dropping a custom loader called IndigoDrop into the Windows Startup folder for persistence. IndigoDrop performed anti-infection checks, fetched Metasploit shellcode, and ultimately loaded an XOR-encoded Cobalt Strike beacon hidden in trojanized jQuery files, while related Python modules conducted reconnaissance and stole browser and Wi-Fi credentials. A separate campaign analyzed by Zscaler used a Word document themed around the India-China border dispute to trigger a macro-delivered PowerShell chain that staged shellcode behind a fake GIF header and installed a Cobalt Strike beacon over HTTPS. The operators used fileless techniques, spoofed HTTP Host headers such as update.windows.microsoft.com, and in some variants injected an RSA-encrypted payload into notepad.exe; researchers also identified infrastructure including 47.240.73.77, 114.67.110.37, and 360doc.com-based command-and-control domains. Across both campaigns, the attackers relied on topical military lures, multi-stage loaders, and legitimate-looking web traffic to conceal remote access activity against likely government and defense-related targets.

Nov 20
Csirt Sk

Aktuålna kampaƈ APT skupiny Qilin zasahuje aj Slovensko | CSIRT.SK

Feb 26
Dfir Report

SEO Poisoning to Domain Control: The Gootloader Saga Continues - The DFIR Report

Dec 18
Seqrite

BATLOADER 2.X Malware Analysis and Attack Tactics | Seqrite

Researchers linked Batloader activity to the Water Minyades / DEV-0569 / SteelClover ecosystem, which used malvertising, SEO poisoning, and fake software download pages to lure victims into installing trojanized packages. The campaigns abused legitimate installer frameworks such as Advanced Installer and WiX, then shifted to obfuscated JavaScript and PyArmor-protected Python loaders that fingerprinted hosts, contacted command-and-control infrastructure, escalated privileges, and attempted to disable security tools. Operators also used cloned software sites and malicious Google ads to distribute MSI files that launched PowerShell, added Microsoft Defender exclusions, and retrieved encrypted follow-on payloads. The infections were used to selectively deploy a broad set of malware, including Qakbot, Ursnif, Vidar, ZLoader, RedLine Stealer, Raccoon Stealer, Cobalt Strike, and remote-management tools such as Atera and Syncro. Trend Micro reported that Batloader infections observed from September 2022 onward were associated with Royal ransomware, while NTT documented a surge of related infections at Japanese companies in early 2023 through the FakeGPG and BatApp campaigns. The activity was concentrated heavily in the United States but also affected Canada, Germany, Japan, and the United Kingdom, underscoring Batloader's role as a flexible initial-access platform for both credential theft and ransomware intrusion chains.

Aug 7
Trend Micro Research

Latest Batloader Campaigns Use Pyarmor Pro for Evasion | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.