None
EN
SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servers
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
A proxy network known as REM Proxy is powered by malware known as SystemBC, offering about 80% of the botnet to its users, according to new findings from the Black Lotus Labs team at Lumen Technologies.
According to Lumen, the SystemBC botnet comprises over 80 C2 servers and a daily average of 1,500 victims, of which nearly 80% are compromised virtual private server (VPS) systems from several large commercial providers.
Each victim has 20 unpatched CVEs and at least one critical CVE on average, with one of the identified VPS servers in the U.S. city of Atlanta vulnerable to more than 160 unpatched CVEs.
One of the largest use cases of the illicit network is by the threat actors behind SystemBC themselves, who use it to brute-force WordPress site credentials.
"Originally used by threat actors to enable ransomware campaigns, the platform has evolved to offer the assembly and sale of bespoke botnets."
['powers'
'systembc'
'threat'
'victims'
'c2'
'80'
'proxies'
'actors'
'servers'
'vps'
'proxy'
'network'
'botnet'
'daily'
'rem']