ATT&CKReferencesTrumanKroll_SYSTEMBCServer_Jan2024

TrumanKroll_SYSTEMBCServer_Jan2024

Truman, D. (2024, January 19). Inside the SYSTEMBC Command-and-Control Server. Retrieved June 18, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareSystemBC

SystemBC has executed a copy of itself as a scheduled task with the `start` command. The copy of SystemBC has random file and directory names within the ProgramData directory.

T1090.003
Multi-hop Proxy
MalwareSystemBC

SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication.

T1105
Ingress Tool Transfer
MalwareSystemBC

SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines.

T1124
System Time Discovery
MalwareSystemBC

SystemBC has leveraged the time of the device to create a text file with a filename that uses the function of `uniqid(time()).‘.txt`, consisting of the 10 character UNIX timestamp and 13 hexadecimal characters.

T1571
Non-Standard Port
MalwareSystemBC

The server component of SystemBC has used various TCP ports for C2 communication.

T1620
Reflective Code Loading
MalwareSystemBC

SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.