Gallagher, S., Gn, S. (2020, December 16). Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor. Retrieved May 16, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
MalwareSystemBC | SystemBC has executed a copy of itself as a scheduled task with the `start` command. The copy of SystemBC has random file and directory names within the ProgramData directory. |
| T1057 Process Discovery |
MalwareSystemBC | SystemBC has the ability to enumerate running processes. |
| T1059.001 PowerShell |
MalwareSystemBC | SystemBC has used hidden scheduled tasks to execute PowerShell commands by adding the following: `-WindowStyle Hidden -ep bypass -file `. |
| T1059.003 Windows Command Shell |
MalwareSystemBC | SystemBC has used `cmd.exe` to execute VBS scripts, BAT scripts and CMD scripts. |
| T1059.005 Visual Basic |
MalwareSystemBC | SystemBC has leveraged VBScript to execute malicious code. |
| T1082 System Information Discovery |
MalwareSystemBC | SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type. |
| T1087.001 Local Account |
MalwareSystemBC | SystemBC has collected the Windows account username on the victim machine. |
| T1090.003 Multi-hop Proxy |
MalwareSystemBC | SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareSystemBC | SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries. |
| T1105 Ingress Tool Transfer |
MalwareSystemBC | SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines. |
| T1106 Native API |
MalwareSystemBC | SystemBC has utilized native Windows API functions such as `EnumWindows`and `GetVolumeInformationA` during discovery activities. |
| T1480 Execution Guardrails |
MalwareSystemBC | SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not. |
| T1564.003 Hidden Window |
MalwareSystemBC | SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows. |
| T1573.001 Symmetric Cryptography |
MalwareSystemBC | SystemBC has encrypted its C2 traffic with RC4. |
| T1678 Delay Execution |
MalwareSystemBC | SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.