logo

SystemBC Malware's C2 Server Analysis Exposes Payload Delivery Tricks

ID: 789b131b-ad62-586b-9270-eaa045125f53

STIX ID: report--789b131b-ad62-586b-9270-eaa045125f53

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-01-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**SystemBC and DarkGate RAT analyses:** Researchers examined SystemBC, a commercially sold RAT that supplies implant binaries, C2 server executables, and a PHP admin panel; SystemBC uses SOCKS5 proxies, opens multiple TCP ports for C2/IPC/bots, and supports on-the-fly modules and shellcode execution to maintain persistent access and deliver additional payloads such as Cobalt Strike and ransomware. The report also covers DarkGate v5.2.3, which shuffles the Base64 alphabet for on-disk encodings but contains a weakness that allows decoding of configuration and keylogger outputs, aiding forensic analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.