SYSTEMBC
SOCKS5 PROXY
DROXIDAT
TOR C2
Threat IntelligenceMalwareFebruary 8, 202615 min read

SystemBC: The Ransomware Enabler Hiding in Plain Sight

Inside the SOCKS5 proxy backdoor that has become the silent backbone of modern ransomware operations — enabling encrypted tunneling, TOR-based C2, and persistent access for the world's most destructive threat actors.

Scroll

SystemBC is a C-language proxy backdoor first observed in June 2019, originally sold as an underground networking tool. It has since evolved into a critical enabler for ransomware operations, providing encrypted SOCKS5 proxy tunneling and TOR-based command-and-control to groups including Ryuk, Conti, DarkSide (Colonial Pipeline), and Black Basta.

Overview & Evolution

SystemBC was initially marketed on Russian-language cybercrime forums as a "proxy bot" for routing traffic through compromised machines. Its primary function — acting as a SOCKS5 proxy with encrypted communications — made it attractive to operators who needed to tunnel malicious traffic through victim networks without triggering network detection.

Current Scale

As of early 2025, SystemBC maintains 80+ active C2 servers and compromises an estimated 1,500 new victims daily. Despite being targeted in Operation Endgame (May 2024), the malware's infrastructure has proven remarkably resilient.

Technical Architecture

Core Functionality

SystemBC operates as a SOCKS5 proxy daemon on compromised hosts. When activated, it opens a local listening port and routes traffic from the operator through the victim machine, enabling the attacker to:

Persistence Mechanisms

Encryption & C2 Protocol

SystemBC's C2 protocol uses a layered encryption scheme:

TOR Integration

SystemBC bundles a lightweight TOR client (mini-tor) that establishes connections to .onion hidden services for C2 communication. This eliminates the need for TOR Browser on the victim and makes C2 traffic significantly harder to block or intercept.

C2 Communication Flow

DroxiDat Variant (2023)

Targeted Attack

In early 2023, a lean SystemBC variant dubbed DroxiDat was deployed against a South African critical infrastructure power utility. The attack was attributed to a threat actor with suspected ties to Russian-speaking groups.

DroxiDat represents a streamlined evolution of SystemBC:

Ransomware Partnerships

RansomwareYearSystemBC Role
Ryuk2020Post-exploitation proxy and persistence
Egregor2020Network tunneling during data exfiltration
Conti2021Standard toolkit component; mentioned in leaked playbooks
DarkSide2021Used in Colonial Pipeline attack infrastructure
Black Basta2022-25Primary proxy tool for lateral movement and staging
Royal / BlackSuit2023-24Proxy persistence alongside Cobalt Strike Beacons
Play2023-24Network tunneling during double extortion operations

MITRE ATT&CK Mapping

TacticTechniqueUsage
ExecutionT1059.003 Windows Command ShellCommand execution via cmd.exe
PersistenceT1547.001 Registry Run KeysAutostart persistence
PersistenceT1053.005 Scheduled TaskRecurring execution tasks
Defense EvasionT1573.001 Encrypted ChannelRC4-encrypted C2 communications
C2T1090.003 Multi-hop ProxySOCKS5 proxy through TOR network
C2T1090 ProxySOCKS5 proxy tunneling for operators
C2T1105 Ingress Tool TransferDownload additional payloads
DiscoveryT1082 System Info DiscoveryHost profiling sent to C2

Linux Variant (2024-2025)

In late 2024, researchers identified a new Perl-based Linux variant of SystemBC, representing a significant platform expansion:

Detection & Defense

Detect & Disrupt Proxy-Based Threats

Mjolnir Security specializes in detecting proxy-based backdoors and ransomware precursor activity before encryption begins.

Proxy DetectionTOR Traffic AnalysisRansomware PreventionIncident ResponseThreat HuntingMDR Services
  • Ransomware Precursor Detection Proactive identification of SystemBC, Cobalt Strike, and other pre-ransomware tools before data exfiltration and encryption stages begin.
  • Network Traffic Analysis Deep inspection of encrypted proxy traffic, TOR connections, and anomalous SOCKS5 activity within your environment.
  • 24/7 Incident Response Rapid containment when proxy-based backdoors are detected. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: February 8, 2026