Cybercriminals Hijack 1,500 VPS Servers Daily to Build Massive Underground Proxy Network

# SystemBC Proxy Botnet: A Global Cybercrime Highway Operating in Plain Sight

The SystemBC proxy botnet has emerged as a major cybercrime infrastructure, operating a network of approximately 1,500 compromised servers daily to facilitate malicious activities worldwide. Active since 2019, this botnet has become a preferred tool for ransomware groups and other threat actors seeking to hide their criminal operations.

## How SystemBC Operates

SystemBC functions as a proxy service that routes malicious traffic through infected servers, effectively masking command-and-control communications and making detection significantly more challenging. The botnet’s operators show little concern for stealth, operating openly without protecting bot IP addresses through obfuscation or rotation techniques.

The network maintains over 80 command-and-control servers that connect clients to infected proxy servers, creating a robust infrastructure for cybercriminal activities.

## Primary Targets and Customers

Research by Lumen Technology’s Black Lotus Labs reveals that SystemBC primarily targets vulnerable commercial virtual private servers (VPS), which comprise nearly 80% of the botnet’s infrastructure. This focus on VPS systems provides several advantages:

– **Extended infection periods**: Nearly 40% of compromised systems remain infected for over a month
– **High-volume traffic capacity**: Individual servers can generate over 16 gigabytes of proxy data in 24 hours
– **Superior stability** compared to residential proxy networks

The botnet serves various criminal customers, including:
– **REM Proxy**: Utilizes approximately 80% of SystemBC’s bots for tiered proxy services
– **Russian web-scraping operations**: Large-scale data harvesting activities
– **VN5Socks/Shopsocks5**: Vietnamese-based proxy network
– **WordPress credential attacks**: SystemBC operators frequently brute-force WordPress login credentials for sale to malicious code brokers

## Vulnerability Exploitation

All infected servers contain multiple security vulnerabilities, with an average of 20 unpatched issues per system and at least one critical-severity flaw. Researchers discovered one Alabama-based system with an alarming 161 unpatched vulnerabilities, highlighting the extensive security gaps that SystemBC exploits.

## Technical Infrastructure

The botnet’s recruitment operations appear centralized around the IP address 104.250.164[.]214, which hosts all 180 SystemBC malware samples. When a server becomes infected, it downloads a Russian-commented shell script that simultaneously executes all SystemBC samples.

## Resilience and Persistence

SystemBC has demonstrated remarkable resilience, surviving law enforcement operations including Operation Endgame, which targeted multiple botnet infrastructures. This persistence, combined with the botnet’s high-volume capabilities and extended infection lifespans, makes it a significant ongoing threat to global cybersecurity.

The botnet’s brazen operational approach and extensive customer base underscore the need for organizations to prioritize VPS security, implement comprehensive vulnerability management programs, and maintain vigilant monitoring for proxy-based threats.

Share This Article