ATT&CKReferencesAhnLab_SystemBC_Apr2022

AhnLab_SystemBC_Apr2022

AhnLab. (2022, April 4). SystemBC Being Used by Various Attackers . Retrieved June 18, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareSystemBC

SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type.

T1095
Non-Application Layer Protocol
MalwareSystemBC

SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries.

T1140
Deobfuscate/Decode Files or Information
MalwareSystemBC

SystemBC has the ability to decrypt RC4 encrypted packets and to decode obfuscated data before C2 communication. Additionally, SystemBC has decrypted its config file that was encoded with XOR and a hardcoded 40-byte key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.