SystemBC (Windows)
Aliases: Coroxy, DroxiDat
- First seen
- 2019-08-01 00:00:00
- Malware type
- downloader, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:39:19
- Profile updated
- 2026-07-07 13:03:08
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Context
SystemBC is a multiplatform proxy malware active since August 2019. It creates SOCKS5 network tunnels in the victim’s network and connects to its C2 server using a custom, RC4-encrypted protocol. It can also download and execute additional malware, with payloads either written to disk or mapped into memory. The SystemBC kit, including the C2 panel, server, and malware executables, is sold in underground forums.
Used by threat actors
- TA577 (threat-actor)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- services.google.com — M Trends 2025 En (report)
- cloud.google.com — Unc4393 Goes Gently Into Silentnight (report)
- Microsoft — Threat Actors Misusing Quick Assist In Social Engineering Attacks Leading To Ransomware (report)
- Mandiant — Melting Unc2198 Icedid To Ransomware Operations (report)
- Mandiant — Chasing Avaddon Ransomware (report)
- CISA — Aa22 249A (report)
- elastic.co — Cuba Ransomware Campaign Analysis (report)
- CrowdStrike — Hypervisor Jackpotting Lack Of Antivirus Support Opens The Door To Adversaries (report)
- mandiant.widen.net — M Trends 2023 (report)
- blog.lumen.com — Systembc Bringing The Noise (report)
- reliaquest.com — Gootloader Infection Credential Access (report)
- web.archive.org — Threat%20Alert%20Gootloader%20 %20Large%20Payload%20Leading%20To%20Compromise%20(Blog) (report)
- youtube.com — Watch (report)
- first.org — Firstcon23 Tlpclear Sood Compromising The Keys To The Kingdom (report)
- logpoint.com — Defending Against 8Base (report)
- blogs.vmware.com — 8Base Ransomware A Heavy Hitting Player (report)
- news.sophos.com — Nearly Half Of Malware Now Use Tls To Conceal Communications (report)
- arcticwolf.com — Greedy Sponge Targets Mexico With Allakore Rat And Systembc (report)
- esentire.com — Esentire Threat Intelligence Malware Analysis Batloader (report)
- intel471.com — Cobalt Strike Cybercriminals Trickbot Qbot Hancitor (report)
- rapid7.com — Ongoing Social Engineering Campaign Refreshes Payloads (report)
- securityintelligence.com — Trickbot Conti Crypters Where Are They Now (report)
- rapid7.com — Black Basta Ransomware Campaign Drops Zbot Darkgate And Custom Malware (report)
- kroll.com — Black Basta Technical Analysis (report)