The SystemBC trail: 1,570 victims exposed after ransomware attack
An investigation reveals a botnet linked to 'The Gentlemen' ransomware that uses SystemBC to infiltrate corporate systems.

The resurgence of SystemBC in ransomware operations
Global cybersecurity is facing a new threat. Recent investigations by Check Point have brought to light a command-and-control (C2) infrastructure linked to the ransomware group known as The Gentlemen. This group, which operates under the Ransomware-as-a-Service (RaaS) model, has been detected using the SystemBC proxy malware to solidify its presence in compromised networks.
The findings are alarming: the C2 server analyzed has allowed for the identification of more than 1,570 victims globally. This figure highlights the ability of threat actors to scale their operations through the use of sophisticated persistence tools.
How does this botnet operate?
The primary technique of SystemBC consists of establishing SOCKS5 network tunnels. This allows attackers to maintain a persistent and encrypted connection with infected systems, facilitating lateral movement within the victim's infrastructure before deploying the final encryption payload.
"SystemBC establishes SOCKS5 network tunnels that allow attackers to evade conventional security measures and maintain control over compromised assets for extended periods."
The importance of cybersecurity hygiene
This incident is a reminder that any unpatched vulnerability can become the gateway for a massive hack. Proactive patch management is the first line of defense against these types of incursions. If you would like to delve deeper into how security agencies manage these risks, you can consult our guide on CISA warns of new vulnerability: critical deadlines for patches.
Conclusion: What should organizations do?
To protect themselves against the tactics employed by The Gentlemen and their proxy tools, companies must:
- Monitor network traffic: Identify unusual connections to known C2 servers.
- Constant updates: Implement security patches immediately on all exposed systems.
- Network segmentation: Limit lateral movement, making it difficult for the malware to spread if a computer is infected.
Constant vigilance remains the most effective tool against a rapidly evolving threat landscape.
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...