New SystemBC Malware Variant Targets Southern African Power Company
by JohnCCR - Saturday August 12, 2023 at 04:35 PM
#1
An unknown threat actor has been linked to a cyber attack on a power generation company in southern Africa with a new variant of the SystemBC malware called DroxiDat as a precursor to a suspected ransomware attack.

"The proxy-capable backdoor was deployed alongside Cobalt Strike Beacons in a south African nation's critical infrastructure," Kurt Baumgartner, principal security researcher at Kaspersky's Global Research and Analysis Team (GReAT), said.

The Russian cybersecurity company said the attack, which took place in late March 2023, was in its early stages and involved the use of DroxiDat to profile the system and proxy network traffic using the SOCKS5 protocol to and from command-and-control (C2) infrastructure.

SystemBC is a C/C++-based commodity malware and remote administrative tool that was first seen in 2019. Its main feature is to set up SOCKS5 proxies on victim computers that can then be used by threat actors to tunnel malicious traffic associated with other malware. Newer variants of the malware can also download and run additional payloads.

The use of SystemBC as a conduit for ransomware attacks has been documented in the past. In December 2020, Sophos revealed ransomware operators' reliance on SystemBC RAT as an off-the-shelf Tor backdoor for Ryuk and Egregor infections.

"SystemBC is an attractive tool in these types of operations because it allows for multiple targets to be worked at the same time with automated tasks, allowing for hands-off deployment of ransomware using Windows built-in tools if the attackers gain the proper credentials," the company said at the time.

DroxiDat's links to ransomware deployment stem from a healthcare-related incident involving DroxiDat around the same timeframe in which the Nokoyawa ransomware is said to have been delivered alongside Cobalt Strike.

The malware employed in the attack is both compact and lean when compared to SystemBC, stripped off most of the functionality associated with the latter to act as a simple system profiler and exfiltrate the information to a remote server.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [HOT] CVE-2026-41940: cPanel/WHM Auth Bypass to ROOT - 0-Day Chain Breakdown & PoC Zfruussia 7 513 Yesterday, 05:17 PM
Last Post: phas3lock
  Gmail breach is real or not? dai5 2 240 Yesterday, 01:22 PM
Last Post: dai5
  [OpSec 101] How PomPomPurin got raided azwug 0 173 May 04, 2026, 08:00 PM
Last Post: azwug
  BreachForums Leak Free Data KingJulien 181 14,021 May 04, 2026, 01:55 AM
Last Post: nouseridontthink
  New Security Breach Allegations for Samsung TVs (Europe/UK Region) Tr28 1 309 May 03, 2026, 06:27 AM
Last Post: leojson

Forum Jump:


 Users browsing this forum: 1 Guest(s)