SystemBC, also known as Coroxy and DroxiDat, is a Windows malware family active since at least 2018 that is primarily used as a SOCKS5 proxy and backdoor to provide covert remote access and traffic tunneling on compromised hosts. It is widely used in cybercrime operations, especially as an enabling component for ransomware intrusions, where it helps operators maintain a hidden foothold, relay command-and-control traffic through victim systems, deliver additional payloads, and support post-compromise operations. SystemBC has been associated with numerous criminal ecosystems and ransomware-linked actors, including Conti, Ryuk, DarkSide, Black Basta, Play, Rhysida, Hive, Vice Society, 8BASE, Egregor, Avaddon, Cuba, Maze, and FIN12-linked activity.
SystemBC is commonly deployed after initial access rather than as the first-stage payload. Delivery has been observed through loaders and other malware families, spearphishing campaigns, and earlier exploit-kit activity including RIG and Fallout. It is frequently paired with tooling such as Cobalt Strike and is often installed during broader intrusions that involve reconnaissance, credential abuse, lateral movement, and ransomware staging.
On execution, SystemBC typically gathers basic system and user information, establishes persistence, and prevents duplicate execution through a mutex. Observed persistence mechanisms include scheduled tasks and registry-based autorun methods, and some variants copy themselves into user-accessible or temporary locations before continuing execution. The malware repeatedly attempts to contact command-and-control infrastructure, sends host metadata, and then waits for operator commands or follow-on malware deployment.
A defining feature of SystemBC is its proxying capability. Most documented variants create a SOCKS5 channel that allows attackers to route malicious traffic through infected machines, conceal downstream infrastructure, and blend communications into normal-looking network activity. SystemBC has also been described as supporting encrypted command-and-control, with some newer variants shifting from simpler TCP-based communications toward Tor-like networking to improve stealth and resilience. In addition to proxying, reported capabilities include remote command execution, downloading and launching additional payloads, in-memory execution of binaries and scripts, and support for data exfiltration as part of ransomware or hands-on-keyboard operations.
SystemBC remains in demand in underground markets because it provides reliable covert access and network relay functionality that can be reused across many intrusion types. Its long-term prevalence, modular use in post-compromise workflows, and repeated appearance alongside major ransomware operations make it a significant malware enabler in the contemporary cybercrime ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload.
The primary initial-access vector is exploitation of CVE-2024–55591, an authentication bypass in Fortinet FortiOS and FortiProxy with a CVSS score of 9.8. The vulnerability was disclosed in January 2025; proof-of-concept code circulated quickly, and mass exploitation of unpatched edge devices followed.
multiple ransomware groups, including initial access brokers with ties to Play ransomware operators, are also exploiting three vulnerabilities - CVE-2024-57727 - in remote monitoring and management tool SimpleHelp to conduct remote code execution at many U.S.-based entities
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Attackers leverage credential theft, lateral movement tools (Cobalt Strike, SystemBC), and social engineering (notably by UNC3944/Scattered Spider) to escalate privileges and deploy Linux-based ESXi encryptors.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.
Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.
Instead of direct 443 backconnects and SystemBC proxies (with TitanPlus registry entries), it uses DNS-based C2 via public resolvers.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
SystemBC, also known as Coroxy or DroxiDat, is a malware categorized as Proxy malware, a Bot, a backdoor, and even a RAT... In most versions of SystemBC, it seeks to gather system and user information, establish persistence, and then create a Socks5 connection with the Command and Control (C&C) server, transmitting basic information, and waiting for commands or the launch of other malware by the attacker.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
[TA0003][T1053] Persistence running tasks using start value ... [TA0003][T1053] Persistence creating tasks with random name (File) <RandName>.job > (Path) *\Windows\Tasks\<RandName>.job
[TA0003][T1053] Persistence running tasks using start value ... [TA0003][T1053] Persistence creating tasks with random name (File) <RandName>.job > (Path) *\Windows\Tasks\<RandName>.job
[TA0003][T1053] Persistence running tasks using start value ... [TA0003][T1053] Persistence creating tasks with random name (File) <RandName>.job > (Path) *\Windows\Tasks\<RandName>.job
it might generate a random string for this purpose, or, quite intriguingly, it will deobfuscate (typically using XOR) a domain... while also deobfuscating and decrypting network data it will use for later connections.
it’s common in some versions for SystemBC to launch a version of itself... in temporary paths like ProgramData, Roaming, or Temp.
[TA0005][T1070.004] Auto-delete function to evade file detection (Command) cmd.exe*/C*ping*{IP}*-n*{Number}*-w*{Number}*>*Null & Del*
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
Command and Control: Monitor for anomalous outbound traffic over non-standard ports or traffic matching known SystemBC communication signatures
[TA0011][T1090] Connection outside through a file in a temporary path (Path) *ProgramData* | *AppData* > (NetConnection) Public IP {Non common country|Direction}
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
155 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family whose communication signatures are recommended for monitoring in relation to The Gentlemen activity.
A SOCKS5 proxy used for covert command-and-control tunneling and persistence in The Gentlemen intrusions.
Windows malware that functions as a SOCKS5 proxy, backdoor, and remote access tool. It tunnels attacker traffic through infected hosts, establishes encrypted C2 communications, executes commands and payloads including EXE, DLL, shellcode, VBS, BAT, CMD, and PowerShell, supports in-memory execution, and maintains persistence via scheduled tasks and Run keys.
Backdoor/proxy malware whose infrastructure was targeted in prior Operation Endgame actions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.