#SystemBC
The bots have started scouring my site. They're looking for all sorts of specific filenames that I assume are common exploits or frequently-exposed data.

/wp-content? 404
/.aws/credentials? 404
/administrator/index.php 404 lol
/systembc/password.php? 404 bitch
/config/secrets.json are you KIDDING?
April 11, 2025 at 6:40 PM
Huge cybercrime news here. Authorities say they’ve disrupted six types of botnets/loaders/cybercrime infrastructure: IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot #infosec www.europol.europa.eu/media-press/...
Largest ever operation against botnets hits dropper malware ecosystem | Europol
Between 27 and 29 May 2024 Operation Endgame, coordinated from Europol’s headquarters, targeted droppers including, IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot. The actions focused ...
www.europol.europa.eu
May 30, 2024 at 5:21 AM
Binary Ninja scripting tricks, a simple showcase of their BinaryView object with Python to easily pull out encrypted data and reimplement a loop to extract an embedded second stage payload -- in a previous SystemBC malware sample! 😁 https://youtu.be/kgyRiQqc1FU
January 17, 2025 at 2:00 PM
"The threat actors repeatedly leveraged remote services to facilitate lateral movement within the network. Their activity began with the deployment of SystemBC and GhostSOCKS proxy tools to a domain controller."

🌟New report out Monday, January 27th by @r3nzsec, @MyDFIR & @MittenSec!
January 25, 2025 at 2:33 PM
🚨 After Windows, the #SystemBCRAT is now targeting Linux systems helping Ryuk, Conti, and other ransomware spread.

Read: hackread.com/systembc-rat...

#CyberSecurity #Malware #Linux #Ransomware
SystemBC RAT Now Targets Linux, Spreading Ransomware and Infostealers
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 11, 2025 at 1:21 PM
SystemBC RAT Now Targets Linux, Spreading Ransomware and Infostealers hackread.com/systembc-rat...
SystemBC RAT Now Targets Linux, Spreading Ransomware and Infostealers
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 11, 2025 at 6:49 PM
SystemBC RAT now targets Linux, enabling ransomware gangs like Ryuk & Conti to spread, evade detection, and maintain encrypted C2 traffic for stealthy cyberattacks.

hackread.com/systembc-rat...
SystemBC RAT Now Targets Linux, Spreading Ransomware and Infostealers
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 11, 2025 at 2:28 PM
🥷
Grosse op contre l’écosystème #malware par @Europol

✅ arrestations
✅ suspension de serveurs
✅ prise de contrôle de sites liés
Largest ever operation against botnets hits dropper malware ecosystem | Europol
Between 27 and 29 May 2024 Operation Endgame, coordinated from Europol’s headquarters, targeted droppers including, IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot. The actions focused ...
www.europol.europa.eu
May 30, 2024 at 6:37 AM
🔥Following the massive botnet takedown codenamed Operation Endgame in May ‘24, which shut down the biggest malware droppers, including IcedID,SystemBC, Pikabot, Smokeloader & Bumblebee, law enforcement agencies across North America & Europe dealt another blow to the malware ecosystem in early 2025.
💻🌐 Five detentions and interrogations as well as server takedowns in follow-up of botnet takedown Operation Endgame.

Read more in our press release ⤵️

www.europol.europa.eu/media-press/...
April 10, 2025 at 3:24 PM
Threat actors target a South African nation's power generator with malware
https://securelist.com/focus-on-droxidat-systembc/110302/
August 11, 2023 at 9:58 AM
The Gentlemen Ransomware Expands With Rapid Affiliate Growth - Infosecurity Magazine www.infosecurity-magazine.com/news/gentlem...
The Gentlemen Ransomware Expands With Rapid Affiliate Growth
Gentlemen RaaS expands quickly with multi-platform attacks and SystemBC-linked infections
www.infosecurity-magazine.com
April 22, 2026 at 6:09 AM
New @deciphersec.bsky.social podcast for your earballs!

💻 New CISA directive to yeet old edge security devices
🤖 New SystemBC botnet activity research from @silentpush.bsky.social
🎬 The sheer joy of JOYBUBBLES from @charmingstranger.com

open.spotify.com/episode/5EgP...
Dumping Edge Security Devices, the SystemBC Botnet, and the Joy of Joybubbles
open.spotify.com
February 6, 2026 at 4:04 PM
Der Einsatz habe sich vor allem gegen die Gruppierungen hinter den sechs Schadsoftware-Familien "IcedID", "SystemBC", "Bumblebee", "Smokeloader", "Pikabot" und "Trickbot" gerichtet. Diese Programme werden als sogenannte Dropper genutzt, die als Türöffner für das Eindringen in Netzwerke dienen
BKA meldet "bisher größten Schlag" gegen weltweite Cyberkriminalität
Deutsche Sicherheitsbehörden haben in einer internationalen Aktion den "bisher größten Schlag" weltweit gegen Cyberkriminelle ausgeführt. Vier Menschen wurden festgenommen und zehn internationale Haft...
www.tagesschau.de
May 30, 2024 at 11:14 AM
SystemBC botnet compromises 1,500 VPS servers daily, enabling high-volume DDoS attacks. Stay vigilant and enhance your cybersecurity measures. #CyberSecurity #DDoS #SystemBC Link: thedailytechfeed.com/systembc-bot...
September 19, 2025 at 4:20 PM
Another day, another #Amadey 📅👀 This time dropping #SystemBC ⤵️

Amadey botnet C2:
📡cobolrationumelawrtewarms .com
📡107.189.27.66 (AS14956 ROUTERHOSTING 🇳🇱)

SystemBC payload:
📄https://bazaar.abuse.ch/sample/c13d59dc2e8ee1cbdb8016de0fb3b374f827406fa5d2d1aa4a2820170816d131/
March 7, 2025 at 6:14 PM
Global SystemBC Botnet Found Active Across 10,000 Infected Systems - Infosecurity Magazine www.infosecurity-magazine.com/news/global-...
Global SystemBC Botnet Found Active Across 10,000 Infected Systems
SystemBC malware linked to 10,000 infected IPs, posing risks to sensitive government infrastructure
www.infosecurity-magazine.com
February 8, 2026 at 4:28 PM
As part of Operation Endgame we shared an initial one-off Special Report on SystemBC bot infections: shadowserver.org/what-we-do/n...

Dashboard map view: dashboard.shadowserver.org/statistics/c...

Details on Operation Endgame coordinated by Europol EC3:
europol.europa.eu/media-press/...
June 5, 2024 at 3:23 PM
-GOLD SALEM and ShinyHunters profiles
-Shai-Hulud worm reaches 500 packages
-New CoinbaseCartel extortion group
-SystemBC botnet returns
-CopyCop info-ops infrastructure expands
-TA415 abuses VSCode tunnels
-Pixie Dust is still exploitable
-Chrome zero-day
-Companies pull out of ATT&CK evaluations
September 19, 2025 at 9:55 AM
SystemBC Botnet Hacked 1,500 VPS Servers Daily to Hire for DDoS Attack
SystemBC Botnet Hacked 1,500 VPS Servers Daily to Hire for DDoS Attack
cybersecuritynews.com
September 19, 2025 at 1:49 PM
A new social engineering campaign by the #BlackBasta #ransomware group targets users with credential theft and #malware attacks, using fake IT support calls via #Microsoft Teams to trick them into downloading software like #AnyDesk.
thehackernews.com/2024/08/blac...
#cybersecurity
Black Basta-Linked Attackers Target Users with SystemBC Malware
Black Basta-linked campaign uses fake IT calls, AnyDesk, and SystemBC malware for credential theft and data exfiltration.
thehackernews.com
August 16, 2024 at 3:20 AM
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate.
www.bleepingcomputer.com
April 20, 2026 at 8:38 PM
--SystemBC malware affects 10K IP addresses,
--DragonForce draws from organized crime playbook,
--Multiple flaws in n8n open-source workflow automation platform allow host take-over,
--Intruder gained AWS cloud environment admin privileges in 10 minutes, 3/4
February 5, 2026 at 2:37 PM
Silent Push's analysis shows SystemBC infections are globally distributed at scale, with the highest concentration of infected IP addresses observed in the United States, followed by Germany, France, Singapore, and India.
www.silentpush.com/blog/systembc/
Silent Push Identifies More Than 10,000 Infected IPs as Part of SystemBC Botnet Malware Family
Silent Push Preemptive Cyber Defense Analysts identified more than 10,000 unique infected IP addresses associated with the SystemBC botnet.
www.silentpush.com
February 5, 2026 at 12:27 AM
SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servers thehackernews.com/2025/09/syst...
SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servers
REM Proxy’s SystemBC botnet infects 1,500 VPS daily across 80 C2 servers, with 40% unpatched for over 31 days, exposing critical vulnerabilities.
thehackernews.com
September 21, 2025 at 7:40 AM