logo

Global SystemBC Botnet Found Active Across 10,000 Infected Systems

ID: 6eae0cea-de35-5982-9d15-9bd275b677ab

STIX ID: report--6eae0cea-de35-5982-9d15-9bd275b677ab

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

...
...

Silent Push research links the long-running SystemBC proxy malware campaign to over 10,000 infected IP addresses globally (highest concentrations in the US, Germany, France, Singapore and India), showing infections persisting an average of 38 days and sometimes over 100 days. The report highlights abuses of bulletproof hosting, data-center-hosted relays (including compromised government sites), and a previously undocumented Perl-based Linux variant undetected by 62 AV engines; SystemBC is commonly observed early in intrusion chains that later deploy ransomware, and defenders are urged to deploy proactive monitoring and fingerprinting to detect infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.