S9001: SystemBC
SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.[1][2][3][4][5]
Security context for executives and security teams
S9001: SystemBC describes [SystemBC](https://attack.mitre.org/software/S9001) is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.[SystemBC](https://attack.mitre.org/software/S9001) executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. [SystemBC](https://attack.mitre.org/software/S9001) was first detected in 2018, and has been us...
Executive priority
S9001: SystemBC is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S9001: SystemBC by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Linux, Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S9001: SystemBC appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
SystemBC
SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.[1][2][3][4][5]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1053.005 | Scheduled TaskSub-technique | |
| Enterprise | T1059.001 | PowerShellSub-technique | |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | |
| Enterprise | T1087.001 | Local AccountSub-technique | |
| Enterprise | T1124 | System Time Discovery | |
| Enterprise | T1105 | Ingress Tool Transfer | |
| Enterprise | T1106 | Native API | |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | |
| Enterprise | T1001 | Data Obfuscation | |
| Enterprise | T1071.004 | DNSSub-technique | SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure.CitationHarmonProofpoint_SystemBC_Aug2019 |
| Enterprise | T1571 | Non-Standard Port | |
| Enterprise | T1564.003 | Hidden WindowSub-technique | |
| Enterprise | T1082 | System Information Discovery | |
| Enterprise | T1090.003 | Multi-hop ProxySub-technique | |
| Enterprise | T1480 | Execution Guardrails | SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication.CitationHarmonProofpoint_SystemBC_Aug2019 SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not.[2] |
| Enterprise | T1057 | Process Discovery | |
| Enterprise | T1620 | Reflective Code Loading | |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | |
| Enterprise | T1678 | Delay Execution | |
| Enterprise | T1095 | Non-Application Layer Protocol | |
| Enterprise | T1059.005 | Visual BasicSub-technique |
Groups, software, and campaigns
G0046: FIN7
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]
G0117: Fox Kitten
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.[1][2][3][4]
G0102: Wizard Spider
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | 47c0e31b8714… | ||
| 19.1 | 1.0 | Older bundle | 47c0e31b8714… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]TrumanKroll_SYSTEMBCServer_Jan2024
Truman, D. (2024, January 19). Inside the SYSTEMBC Command-and-Control Server. Retrieved June 18, 2025.
Open source URL - [2]SophosGnGal_SystemBC_Dec2020
Gallagher, S., Gn, S. (2020, December 16). Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor. Retrieved May 16, 2025.
Open source URL - [3]BlackBasta
Antonio Cocomazzi and Antonio Pirozzi. (2022, November 3). Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor. Retrieved March 14, 2023.
Open source URL - [4]AhnLab_SystemBC_Apr2022
AhnLab. (2022, April 4). SystemBC Being Used by Various Attackers . Retrieved June 18, 2025.
Open source URL - [5]Lumen_SystemBC_Sept2025
Black Lotus Labs . (2025, September 18). SystemBC: Bringing the noise. Retrieved December 15, 2025.
Open source URL - [6]Broadcom_SystemBCCoroxy_Nov2023
Broadcom. (2023, November 17). SystemBC (Coroxy) continuous activities. Retrieved December 15, 2025.
Open source URL - [7]Coroxy
(Citation: BlackBasta)(Citation: Broadcom_SystemBCCoroxy_Nov2023)(Citation: Microsoft_Coroxy_Oct2020)
- [8]Microsoft_Coroxy_Oct2020
Microsoft Security Intelligence. (2020, October 30). Backdoor:Win32/Coroxy.A. Retrieved December 15, 2025.
Open source URL - [9]mitre-attackS9001Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
