SystemBC

MITRE ATT&CK: S9001 View on attack.mitre.org

Aliases: Coroxy, SystemBC

First seen
2018-01-01 00:00:00
Malware type
backdoor, downloader, loader
Family
Malware family
Operating systems
linux, windows
Related IoCs
184 (73 malicious)
Last IoC activity
2026-09-01 20:37:57
Profile updated
2026-07-07 13:48:31

Targeted industries: financial-services government-and-public-sector retail-and-hospitality

Context

SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.

Recent IoC activity

73 malicious indicators in Maltiverse are attributed to SystemBC (S9001). The 20 most recently updated:

Detection coverage

  • 2 YARA rules
  • 439 Sigma rules

Malware & tools used

  • PowerShell (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Local Account (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Native API (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Data Obfuscation (attack-pattern)
  • DNS (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Hidden Window (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Process Discovery (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Delay Execution (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Visual Basic (attack-pattern)
  • Scheduled Task (attack-pattern)

Used by threat actors

  • Wizard Spider (threat-actor)
  • Fox Kitten (threat-actor)
  • FIN7 (threat-actor)
  • FIN12 March 2023 Hospital Center Intrusion (campaign)
  • Pikabot Distribution Campaigns 2023 (campaign)

Detection rules

  • TELEKOM_SECURITY_Win_Systembc_20220311 (yara-rule)
  • MALPEDIA_Win_Systembc_Auto (yara-rule)

Reports & references

  • sentinelone.com — Black Basta Ransomware Attacks Deploy Custom Edr Evasion Tools Tied To Fin7 Threat Actor (report)
  • blog.lumen.com — Systembc Bringing The Noise (report)
  • asec.ahnlab.com — 33600 (report)
  • news.sophos.com — Systembc (report)
  • MITRE ATT&CK — S9001 (report)
  • Broadcom/Symantec — Systembc Coroxy Continuous Activities (report)
  • kroll.com — Inside The Systembc Malware Server (report)
  • Microsoft — Malware Encyclopedia Description (report)

External references