SystemBC is a Windows proxy and backdoor distributed as malware-as-a-service and widely used in ransomware intrusion chains. It provides remote access and SOCKS5 proxying, allowing attackers to conceal command-and-control communications and maintain access to compromised environments. Observed variants support encrypted tunneling and communication through Tor. SystemBC implants have been installed for persistence on Windows hosts, including domain controllers, and used to support lateral movement and follow-on payload delivery, including Cobalt Strike.
SystemBC is commonly deployed after an initial compromise rather than serving as the initial infection mechanism. Distribution chains have included Emotet malspam and GootLoader infections originating from SEO-poisoned search results, deceptive download pages, and malicious script archives. A PowerShell backdoor associated with the SystemBC service has also been observed executing in memory and encrypting communications with RC4 during an LV ransomware intrusion following exploitation of Microsoft Exchange ProxyShell vulnerabilities.
SystemBC has been used by Vice Society, Play, Conti-associated operators, Cuba ransomware operators tracked as REF9019, and Storm-0506 during Black Basta intrusions. Its availability to multiple criminal groups means its presence alone does not establish actor attribution. Its primary role in these operations is persistent, concealed access and post-exploitation support, not file encryption. SystemBC infrastructure was among the targets of Operation Endgame in May 2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload.
The primary initial-access vector is exploitation of CVE-2024–55591, an authentication bypass in Fortinet FortiOS and FortiProxy with a CVSS score of 9.8. The vulnerability was disclosed in January 2025; proof-of-concept code circulated quickly, and mass exploitation of unpatched edge devices followed.
multiple ransomware groups, including initial access brokers with ties to Play ransomware operators, are also exploiting three vulnerabilities - CVE-2024-57727 - in remote monitoring and management tool SimpleHelp to conduct remote code execution at many U.S.-based entities
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Attackers leverage credential theft, lateral movement tools (Cobalt Strike, SystemBC), and social engineering (notably by UNC3944/Scattered Spider) to escalate privileges and deploy Linux-based ESXi encryptors.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
36 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SystemBC for establishing persistent command-and-control (C2) via encrypted tunneling.
Vice Society actors have been observed using a variety of tools, including SystemBC, PowerShell Empire, and Cobalt Strike to move laterally.
They harvest credentials (running reg add HKLM\SYSTEM…WDigest to enable plaintext memory retention) and may deploy remote-access or backdoor frameworks such as Cobalt Strike or SystemBC before encryption.
After gaining access to the victim’s environment, the threat actor deployed SystemBC as the primary Command and Control (C2) backdoor.
After gaining access to the victim’s environment, the threat actor deployed SystemBC as the primary Command and Control (C2) backdoor.
After gaining access to the victim’s environment, the threat actor deployed SystemBC as the primary Command and Control (C2) backdoor.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
A colleague of mine recently came across a SystemBC sample that is protected with VMProtect 3.6 or higher... The sample is packed twice, so after VMProtect has finished initialization, another layer of packer code runs and unpacks the final SystemBC malware.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
SystemBC for establishing persistent command-and-control (C2) via encrypted tunneling.
It is also linked to the increased use of Tor and other TLS-based network proxies to encapsulate malicious communications between malware and the actors deploying them.
there’s also a significant fraction of TLS communications that use an Internet Protocol port other than 443—such as malware using a Tor or SOCKS proxy over a non-standard port number.
Frequently, droppers and loaders use legitimate websites and cloud services with built-in TLS support to further disguise the traffic.
A Node.js runtime is downloaded from nodejs[.]org... ffmpeg pulled from gyan[.]dev... Chisel tunneling client... and win.exe... fetched from external infrastructure.
Attackers ... may deploy remote-access or backdoor frameworks such as Cobalt Strike or SystemBC before encryption. The MITRE context lists "Remote Access Software".
The adversary then began chaining proxy access via plink and Ngrok to traverse the victim’s network segmentation.
551 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Provides concealed command-and-control communication, traffic tunneling, and persistent access for ransomware operators. Targeted by Operation Endgame in May 2024; the article reports subsequent infrastructure resurfacing.
Mentioned solely as a comparison; the content contrasts PaperPhone with SystemBC and explicitly states that the PaperPhone investigation does not establish compromise of servers.
A malware-as-a-service proxy/backdoor used to provide persistent C2 and SOCKS proxy traffic. In this operation it was deployed as s64.dll and srvmtr.exe and persisted through the end of the capture.
Proxy malware botnet; a botnet of more than 1,500 hosts was linked to an affiliate of the Gentlemen ransomware group.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.