Netskope Threat Labs

SystemBC

ATP Sandbox Adv. HeuristicsAV

SystemBC is a proxy malware used for maintaining persistence and hiding traffic, and its operators rent it out as infrastructure for other criminal crews. Infected systems run a SOCKS5 proxy that relays criminal traffic, masking the true origin of intrusions, and the malware also functions as a loader for additional payloads. Major ransomware operations have used it for staging, and its dual role as proxy and loader makes it a fixture of modern intrusion chains.

First seen
March 2022
Last seen
October 2026
CoroxySystembc

21 techniques across 4 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Backdoor.Systembc
ByteCode-MSIL.Trojan.Coroxy
ByteCode-MSIL.Trojan.SystemBC
Gen:Variant.Coroxy.7
Gen:Variant.Coroxy.8
Script-PowerShell.Backdoor.Systembc
Script-PowerShell.Trojan.SystemBC
Win32.Backdoor.Coroxy
Win32.Backdoor.Systembc
Win32.Backdoor.SystemBC