The SystemBC botnet marks a significant development in proxy- based criminal infrastructure .

Instead of exploiting home devices for proxying, SystemBC operators have turned to exploiting large commercial Virtual Private Servers (VPS), enabling high-volume proxy services, with minimal disruption to end users.
In recent months, Lumen Technologies has observed an average of 1,500 compromised VPS systems per day. Each of these is being recruited to carry malicious traffic on behalf of criminal groups.
These compromised servers act as powerful, high-bandwidth proxies, offering an unprecedented level of throughput that traditional home botnets cannot support.
SystemBC Botnet
SystemBC was originally reported by Proofpointin 2019. Since then, its functionality has expanded beyond simple proxy functions.
See also: Qilin ransomware: Breaches 104 organizations in August
After successful infiltration, the loader decrypts a hard-coded configuration and establishes a connection to one of over 80 command and control (C2) servers.
The payload uses a combination of encryption XOR and RC4 to secure its communication channel, ensuring that detection and analysis by network defenders remains difficult.
Lumen analysts discovered this cryptographic path during dynamic analysis of a Linux sample, revealing a three-stage process for both outbound beaconing and C2 responses.
This constant game of cat and mouse, between evasion and detection, has highlighted the resilience of the SystemBC botnet for many years.
The impact of this botnet has been felt across the entire cybercrime ecosystem. In addition to providing proxies for rent, the SystemBC network has been integrated into larger offerings such as REM Proxy, a multi-tier commercial service that serves many criminal enterprises. REM Proxy’s high-end “Mix-Speed” tier includes numerous SystemBC-infected servers, valued for their volume and stability.

Meanwhile, lower-quality proxies are used in brute-force and credential harvesting. This dual use of compromised VPS assets highlights how threat actors optimize the discrete stages of infection and exploitation under a single unified architecture.
See also: Russian Gamaredon and Turla install Kazuar Backdoor in Ukraine
Infection mechanism and decryption process
The infection mechanism often begins with an opportunistic scan of services exposed to the internet on port 443. Once a vulnerable VPS server is identified, the malware download begins via HTTP on port 80.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The recovered shell script automates the parallel download and execution of over 180 SystemBC samples. Each sample shares a 40-byte XOR key embedded in its binary. Upon execution, the loader reconstructs its C2 configuration
Once decrypted, the configuration yields a list of C2 endpoints and operational parameters. The loader then creates an initial beacon packet (consisting of a key, padding bytes, and a 0xFFFF header) encrypted in the same pipeline before transmission.
The response from the C2 server contains a four-byte header indicating commands: create a new proxy, proxy data injection, or terminate.
Lumen researchers noted that this symmetric encryption approach effectively evades signature-based detection while keeping the computational load on compromised servers low.
See also: HybridPetya Ransomware: Is it different from Petya and NotPetya?
Through its combination of scalable infection tactics, strong encryption , and integration into commercial proxy services, SystemBC exemplifies a modern malware-as-a-service model.
Continuous monitoring and rapid notification of breach indicators remain critical to addressing the widespread threat.

Botnet protection
To protect against this threat, it is important to software and operating system your device's. Botnet attacks often exploit known vulnerabilities.
It is also essential to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.
Using strong passwords and changing them regularly is another way to protect yourself from Botnets. Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect your accounts.
Finally, information security training can be particularly useful. Understanding how botnet attacks work can help you identify and avoid attacks.
