logo

SystemBC Botnet Hijacked 10,000 Devices Worldwide to Use for DDoS Attacks

ID: 902db2be-5ae8-52d9-81c1-10f1020d75b1

STIX ID: report--902db2be-5ae8-52d9-81c1-10f1020d75b1

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Executive summary: The report details the SystemBC botnet — a resilient backconnect/SOCKS5 malware infrastructure controlling over 10,000 compromised systems worldwide (notably ~4,300 in the U.S.) that persists for weeks to months and is used as a precursor to ransomware and other criminal operations. Silent Push researchers identified a previously undocumented Perl variant (initially undetected by AV) deployed via UPX-packed ELF droppers (“SafeObject” and “StringHash”) that search writable directories and launch many embedded payloads; the infrastructure has adapted post-law-enforcement takedowns by shifting focus toward hosting providers, increasing persistence and operational utility. Organizations are advised to prioritize proactive monitoring for these indicators and backconnect activity to prevent escalation to data theft or ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.