Description
SystemBC is a proxy malware used for maintaining persistence and hiding traffic, and its operators rent it out as infrastructure for other criminal crews. Infected systems run a SOCKS5 proxy that relays criminal traffic, masking the true origin of intrusions, and the malware also functions as a loader for additional payloads. Major ransomware operations have used it for staging, and its dual role as proxy and loader makes it a fixture of modern intrusion chains.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Also known as
CoroxySystembc
MITRE ATT&CK techniques
21 techniques across 4 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Backdoor.Systembc |
| ByteCode-MSIL.Trojan.Coroxy |
| ByteCode-MSIL.Trojan.SystemBC |
| Gen:Variant.Coroxy.7 |
| Gen:Variant.Coroxy.8 |
| Script-PowerShell.Backdoor.Systembc |
| Script-PowerShell.Trojan.SystemBC |
| Win32.Backdoor.Coroxy |
| Win32.Backdoor.Systembc |
| Win32.Backdoor.SystemBC |