Skip to content
You can now search across every topic, entity and event.What's new
SystemBC
Technology

SystemBC

Modular C2 framework and SOCKS5 proxy used by ransomware groups for covert infrastructure.

SystemBC, a SOCKS5 proxy malware sold as crimeware since 2019, let Check Point Research trace The Gentlemen ransomware group's command infrastructure to at least 1,570 victims in May 2026.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Timeline for SystemBC

#12 2 Aug

Mentioned in: Qilin's own affiliate now outposts it

Cybersecurity: Threats and Defences
#3 19 Apr

KB5091157, Gentlemen C2 intel, ENISA CNAs: in brief

Cybersecurity: Threats and Defences
View full timeline →

Background

SystemBC is a modular command-and-control (C2) framework and SOCKS5 proxy malware commercially offered as crimeware since at least 2019. It gives threat actors an encrypted, proxied communications channel between compromised hosts and attacker-controlled infrastructure, routing C2 traffic through SOCKS5 tunnels to obscure server locations and evade network-based detection. It is typically deployed as a secondary payload after initial access, providing persistent, stealthy connectivity for later attack phases including ransomware staging.

SystemBC has been observed in intrusions associated with multiple ransomware-as-a-service groups and access brokers, including Ryuk, Conti, LockBit and ALPHV/BlackCat affiliates. Its modular architecture lets operators load additional plugins over the established C2 channel, and the SOCKS5 proxy capability is valued because it routes subsequent tooling through the victim network, making external detection difficult without inspecting encrypted traffic.

In May 2026, Check Point Research used SystemBC C2 telemetry, tracking beacon patterns, infrastructure clustering and timing correlation, to surface a victim cluster of over 1,570 organisations linked to The Gentlemen ransomware group, identifying the scale and geography of that operation before many victims had publicly disclosed breaches .

Common Questions
What is SystemBC malware?
SystemBC is a crimeware framework that provides attackers with an encrypted SOCKS5 proxy channel between compromised computers and attacker infrastructure. It is sold to ransomware operators and used to maintain covert C2 access while hiding true server locations from network defenders.
Which ransomware groups use SystemBC?
SystemBC has been used by affiliates of multiple ransomware groups including Ryuk, Conti, LockBit, ALPHV/BlackCat, and The Gentlemen. It functions as a shared-access tool in the ransomware-as-a-service ecosystem, available for purchase to any operator.
How did researchers identify Gentlemen ransomware victims using SystemBC?
Check Point Research tracked SystemBC command-and-control beacon patterns, infrastructure clustering, and timing correlations across The Gentlemen group's C2 network, identifying over 1,570 victim organisations before many had disclosed breaches publicly.Source: event
Source Material