
SystemBC
Modular C2 framework and SOCKS5 proxy used by ransomware groups for covert infrastructure.
SystemBC, a SOCKS5 proxy malware sold as crimeware since 2019, let Check Point Research trace The Gentlemen ransomware group's command infrastructure to at least 1,570 victims in May 2026.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Timeline for SystemBC
Mentioned in: Qilin's own affiliate now outposts it
Cybersecurity: Threats and DefencesKB5091157, Gentlemen C2 intel, ENISA CNAs: in brief
Cybersecurity: Threats and DefencesBackground
SystemBC is a modular command-and-control (C2) framework and SOCKS5 proxy malware commercially offered as crimeware since at least 2019. It gives threat actors an encrypted, proxied communications channel between compromised hosts and attacker-controlled infrastructure, routing C2 traffic through SOCKS5 tunnels to obscure server locations and evade network-based detection. It is typically deployed as a secondary payload after initial access, providing persistent, stealthy connectivity for later attack phases including ransomware staging.
SystemBC has been observed in intrusions associated with multiple ransomware-as-a-service groups and access brokers, including Ryuk, Conti, LockBit and ALPHV/BlackCat affiliates. Its modular architecture lets operators load additional plugins over the established C2 channel, and the SOCKS5 proxy capability is valued because it routes subsequent tooling through the victim network, making external detection difficult without inspecting encrypted traffic.
In May 2026, Check Point Research used SystemBC C2 telemetry, tracking beacon patterns, infrastructure clustering and timing correlation, to surface a victim cluster of over 1,570 organisations linked to The Gentlemen ransomware group, identifying the scale and geography of that operation before many victims had publicly disclosed breaches .