Researchers reported that SystemBC evolved from a Windows SOCKS5 backconnect proxy delivered through RIG and Fallout exploit kits into a broader malware-as-a-service platform used by multiple cybercrime groups. Early campaigns tied the malware to Danabot and AZORult delivery, with the implant tunneling command-and-control traffic and obscuring follow-on activity through infected hosts. Technical analysis showed SystemBC used encrypted configuration data, RC4-protected communications, and support for .bit domain resolution, while underground advertising indicated it was being sold as a dedicated proxy service for other operators.
Later reporting linked SystemBC customers to TrickBot, QBot, and IcedID activity and described a TOR-based sales and build system that allegedly generated more than $100,000 in malware build revenue. Investigators said they identified infrastructure behind the service, recovered customer build data and panel components, and observed some deployments tasking bots to fetch Cobalt Strike payloads. A newer PowerShell variant, socks5.ps1, embedded command-and-control details, registered infected hosts with host metadata, and launched PowerShell jobs to proxy traffic, reinforcing SystemBC's role as a post-compromise access layer increasingly associated with enterprise ransomware operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Bitsight reported in September 2022 that it had observed more than 56,000 unique IP addresses infected with SystemBC since early August, showing the malware remained active globally despite declining use versus prior years. The report also documented newer multipurpose variants used to maintain footholds and deploy tools such as Cobalt Strike and PoshC2, and published associated backconnect C2 servers.
Proofpoint noted that the Twitter account @nao_sec observed SystemBC in connection with a Fallout exploit kit campaign. This provided an additional independent sighting of the malware in 2019 exploit activity.
Between July 18 and July 22, 2019, Proofpoint observed SystemBC distributed by Amadey Loader in a RIG exploit kit campaign. Its appearance across separate exploit kit operations suggested the malware was shared or sold across multiple actors.
On June 6, 2019, Proofpoint again observed SystemBC delivered via Fallout exploit kit, this time alongside PowerEnum and Danabot. The repeat delivery supported the assessment that SystemBC was being used operationally in active crimeware campaigns.
On June 4, 2019, Proofpoint observed SystemBC delivered in a Fallout exploit kit campaign. The malware functioned as a SOCKS5 backconnect proxy and was documented with associated indicators including a SHA-256 hash and C2 hostname.
Proofpoint cited Vitali Kremez as having observed a SystemBC sample. This is one of the earliest explicit sightings of the malware in the wild referenced in the sources.
Proofpoint found an underground forum advertisement for a "socks5 backconnect system" matching SystemBC functionality. The ad showed a control panel and builder for generating customized samples, indicating the malware was being sold commercially.
Walmart Global Tech reported that SystemBC had been sold as a proxy bot since at least April 2019. This anchors the malware's early commercialization before its later evolution into a broader malware-as-a-service platform.
Walmart Global Tech documented a PowerShell version of SystemBC after a researcher found an open directory containing a SystemBC package with socks5.ps1. The analysis described its registration protocol, RC4-style encryption, proxy job handling, persistence artifact, and detection opportunities.
Walmart Global Tech reported identifying the server behind SystemBC's TOR service at 107.175.150[.]179 and recovering stub files, backend data, and a database mapping purchases to build IDs. The analysis linked customers to TrickBot, QBot, and IcedID activity and estimated the operator earned more than about $100,000 from build sales.
Proofpoint published analysis describing SystemBC as a previously undocumented Windows proxy malware used in Fallout and RIG exploit kit campaigns. The report named the malware, detailed its SOCKS5 proxy behavior and cryptography, and linked it to an underground sales advertisement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcebitsight.com
Open sourcemedium.com
Open sourcemedium.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.