A new malware targeting Windows systemshas appeared and looks very threatening. It is called SystemBC and it installs a proxy server on infected computers.
The most worrying thing about the new malware is that it never comes alone. The detection of SystemBC indicates that a computer has also been infected by a second threat.
Proofpoint researchers analyzed the malware and found that its creators are advertising it on underground cybercrime forums.
Essentially, SystemBC can be used in conjunction with other malware .. Attackers can integrate the proxy server provided by SystemBC and infect target computers alongside their main malware
The main role of SystemBC is to create a SOCKS5 proxy server, through which other malware can bypass firewalls and content filters on the Internet. It can also connect to the command-and-control server without revealing its real IP address.

SystemBC is sold to other malware creators
SystemBC was first detected in May. However, Proofpoint researchers discovered an advertisement on a hacking forum for an anonymous malware that appears to be SystemBC and has been around since April.
Initially, the malware was only detected in a few campaigns. However, researchers have noticed that in the last two months, the malware has been distributed via exploit kits, such as RIG and Fallout.
Exploit kits are online systems that exploit browser vulnerabilities to install malware on computers or redirect users to webpages.
Researchers reported that the DanaBot banking trojan and Maze ransomware have used SystemBC's proxying capabilities to hide their malicious activity.
As SystemBC covers malicious network traffic generated by other malware, it is becoming increasingly popular among hackers.
The key point here is that if SystemBC is detected, there will definitely be a second malware on your computer. Therefore, removing SystemBC will not solve your problems.
