Global SystemBC Botnet Found Active Across 10,000 Infected Systems
ID: 6eae0cea-de35-5982-9d15-9bd275b677ab
STIX ID: report--6eae0cea-de35-5982-9d15-9bd275b677ab
Feed Name: Infosecurity Magazine (News)
Silent Push research links the long-running SystemBC proxy malware campaign to over 10,000 infected IP addresses globally (highest concentrations in the US, Germany, France, Singapore and India), showing infections persisting an average of 38 days and sometimes over 100 days. The report highlights abuses of bulletproof hosting, data-center-hosted relays (including compromised government sites), and a previously undocumented Perl-based Linux variant undetected by 62 AV engines; SystemBC is commonly observed early in intrusion chains that later deploy ransomware, and defenders are urged to deploy proactive monitoring and fingerprinting to detect infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
