SystemBC

S9001

Malware.View on attack.mitre.org

About this malware

SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1001
Data Obfuscation

SystemBC has encoded with XOR and encrypted with RC4 its beacon.

T1053.005
Scheduled Task

SystemBC has executed a copy of itself as a scheduled task with the `start` command. The copy of SystemBC has random file and directory names within the ProgramData directory.

T1057
Process Discovery

SystemBC has the ability to enumerate running processes.

T1059.001
PowerShell

SystemBC has used hidden scheduled tasks to execute PowerShell commands by adding the following: `-WindowStyle Hidden -ep bypass -file `.

T1059.003
Windows Command Shell

SystemBC has used `cmd.exe` to execute VBS scripts, BAT scripts and CMD scripts.

T1059.005
Visual Basic

SystemBC has leveraged VBScript to execute malicious code.

T1071.004
DNS

SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure.

T1082
System Information Discovery

SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type.

T1087.001
Local Account

SystemBC has collected the Windows account username on the victim machine.

T1090.003
Multi-hop Proxy

SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication.

T1095
Non-Application Layer Protocol

SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries.

T1105
Ingress Tool Transfer

SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines.

T1106
Native API

SystemBC has utilized native Windows API functions such as `EnumWindows`and `GetVolumeInformationA` during discovery activities.

T1124
System Time Discovery

SystemBC has leveraged the time of the device to create a text file with a filename that uses the function of `uniqid(time()).‘.txt`, consisting of the 10 character UNIX timestamp and 13 hexadecimal characters.

T1140
Deobfuscate/Decode Files or Information

SystemBC has the ability to decrypt RC4 encrypted packets and to decode obfuscated data before C2 communication. Additionally, SystemBC has decrypted its config file that was encoded with XOR and a hardcoded 40-byte key.

View all 21 procedure examples

Groups that use it3

Campaigns0

None recorded.

References5

  1. AhnLab_SystemBC_Apr2022 Open source
    AhnLab. (2022, April 4). SystemBC Being Used by Various Attackers . Retrieved June 18, 2025.
  2. BlackBasta Open source
    Antonio Cocomazzi and Antonio Pirozzi. (2022, November 3). Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor. Retrieved March 14, 2023.
  3. Lumen_SystemBC_Sept2025 Open source
    Black Lotus Labs . (2025, September 18). SystemBC: Bringing the noise. Retrieved December 15, 2025.
  4. SophosGnGal_SystemBC_Dec2020 Open source
    Gallagher, S., Gn, S. (2020, December 16). Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor. Retrieved May 16, 2025.
  5. TrumanKroll_SYSTEMBCServer_Jan2024 Open source
    Truman, D. (2024, January 19). Inside the SYSTEMBC Command-and-Control Server. Retrieved June 18, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.