SystemBC (c30929fb-28a1-407c-a1c3-a83374c63267)
SystemBC is a commodity backdoor malware used as a Tor proxy and remote access Trojan (RAT). It was used during the high-profile 2021 Colonial Pipeline DarkSide ransomware attack and has since been used as a persistence & lateral movement tool during other ransomware compromises, including intrusions involving Ryuk, Egregor, and Play.[BlackBerry SystemBC June 10 2021][Sophos SystemBC December 16 2020][WithSecure SystemBC May 10 2021][Trend Micro Play Ransomware September 06 2022] According to Mandiant's 2023 M-Trends report, SystemBC was the second most frequently seen malware family in 2022 after only Cobalt Strike Beacon.[TechRepublic M-Trends 2023]
Malpedia (Research): https://malpedia.caad.fkie.fraunhofer.de/details/win.systembc
Malware Bazaar (Samples & IOCs): https://bazaar.abuse.ch/browse/tag/systembc/
PulseDive (IOCs): https://pulsedive.com/threat/SystemBC