SystemBC Malware's C2 Server Analysis Exposes Payload Delivery Tricks
ID: 789b131b-ad62-586b-9270-eaa045125f53
STIX ID: report--789b131b-ad62-586b-9270-eaa045125f53
Feed Name: The Hacker News
**SystemBC and DarkGate RAT analyses:** Researchers examined SystemBC, a commercially sold RAT that supplies implant binaries, C2 server executables, and a PHP admin panel; SystemBC uses SOCKS5 proxies, opens multiple TCP ports for C2/IPC/bots, and supports on-the-fly modules and shellcode execution to maintain persistent access and deliver additional payloads such as Cobalt Strike and ransomware. The report also covers DarkGate v5.2.3, which shuffles the Base64 alphabet for on-disk encodings but contains a weakness that allows decoding of configuration and keylogger outputs, aiding forensic analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
