SystemBC – Bringing the Noise
· Published 25/09/2025 09:21 · Modified 25/09/2025 14:41
Essential information
- Published
- 25/09/2025 09:21
- Modified
- 25/09/2025 14:41
- Tags
- 2025-09-25 avoslocker botnet cybercrime icedid infrastructure malicious traffic morpheus ngioweb proxy ransomware rem proxy systembc transferloader trickbot vps
- Related entities
- 158 observables, 13 techniques (mitre), 9 malware, 1 others
Description
The SystemBC botnet, composed of over 80 C2s and 1,500 daily victims, primarily targets VPS systems from commercial providers. It creates proxies enabling high volumes of malicious traffic for various criminal threat groups. The network is used by multiple proxy services, including REM Proxy, which offers tiered packages for different cybercriminal needs. SystemBC's infrastructure allows for massive data transfers, with some bots generating over 16 GB of proxy data in 24 hours. The botnet is used for various malicious activities, including brute-forcing WordPress credentials, web-scraping, and supporting ransomware operations. The report highlights the evolving nature of proxy services in the cybercriminal ecosystem and their role in facilitating large-scale attacks.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (158)
85.206.167.14985.206.167.14885.206.167.14785.206.167.14685.206.167.14585.206.167.14485.206.167.14385.206.167.14285.206.167.14185.206.167.14085.206.167.13985.206.167.13885.206.167.13785.206.167.13685.206.167.13585.206.167.13485.206.167.13385.206.167.13285.206.160.6685.206.160.6585.206.160.25085.206.160.22685.206.160.22585.206.160.1385.206.160.11685.206.160.115185.93.89.191185.93.89.190185.93.89.189185.93.89.188185.93.89.187185.93.89.183185.93.89.182185.93.89.181185.93.89.180185.93.89.179185.93.89.178185.93.89.177185.93.89.176185.93.89.175185.93.89.174185.93.89.172185.93.89.171185.93.89.170185.93.89.169185.93.89.168185.93.89.166185.93.89.165185.93.89.164185.93.89.163185.93.89.162185.93.89.159185.93.89.158185.93.89.157185.93.89.156185.93.89.155185.93.89.153185.93.89.152185.93.89.151185.93.89.150185.93.89.149185.93.89.147185.93.89.146185.93.89.145185.93.89.144185.93.89.143185.64.106.97185.64.106.94185.64.106.189185.64.106.186185.64.106.148185.64.106.147185.64.105.8185.64.105.183185.64.105.182185.64.105.12185.64.104.69185.64.104.68185.64.104.55185.64.104.54185.64.104.45185.64.104.44185.64.104.132185.64.104.131185.64.104.125185.64.104.124185.25.49.229185.25.49.221185.25.49.220185.25.49.183185.25.49.182185.25.49.181185.25.49.180185.25.48.97185.25.48.96185.25.48.95185.25.48.49185.25.48.197185.25.48.104185.25.48.102176.46.138.241176.46.138.240176.46.138.239176.46.138.237176.46.138.235176.46.138.234176.46.138.233176.46.138.232176.46.138.229176.46.138.228176.46.138.227176.46.138.226176.46.138.225176.46.138.223176.46.138.222176.46.138.221176.46.138.220176.46.138.219176.46.138.217176.46.138.216176.46.138.215176.46.138.213176.46.138.211176.46.138.210176.46.138.209176.46.138.208176.46.138.207104.250.164.254104.250.164.253104.250.164.252104.250.164.250104.250.164.251104.250.164.248104.250.164.247104.250.164.246104.250.164.242104.250.164.245104.250.164.244104.250.164.241104.250.164.239104.250.164.240104.250.164.238104.250.164.235104.250.164.236104.250.164.234104.250.164.233104.250.164.230104.250.164.228104.250.164.227104.250.164.229104.250.164.226104.250.164.223104.250.164.224104.250.164.222104.250.164.221104.250.164.220104.250.164.2141c74b1195250632f2f1d1a9066f07f6e0a8c12dff40aeb3c1fe22440c97bc8ee
Techniques (MITRE) (13)
-
Brute Force
-
Exfiltration Over Web Service
-
Non-Standard Port
-
Encrypted Channel
-
Web Service
-
Automated Exfiltration
-
Network Service Discovery
-
Data Encoding
-
Phishing
-
Exploit Public-Facing Application
-
External Remote Services
-
Proxy
-
Valid Accounts
Malware (9)
-
FamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FamilyPublished 30/09/2025 05:15 · Modified 30/09/2025 05:15
-
FamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
FamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
FamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
FamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
Others (1)
- Russian Federation