Skip to main content
Back to Blog
20 May 2026, byZebrabyte Breaches and incidents

More than 10,000 servers compromised with a new Linux version of SystemBC malware

More than 10,000 servers compromised with a new Linux version of SystemBC malware

A major cyber threat has recently been discovered: more than 10,000 unique IP addresses have been identified as being infected with a completely new, previously unknown variant of the virus.

O Major cyber threats It was recently discovered: over 10.000 de adrese IP unice They were identified as being infected. Completely new, previously unknown, a malware-ului SystemBCSpecially adapted for sisteme Linux.

The discovery was made by cybersecurity researchers, who identified a Massive network of compromised servers converted into proxy for criminal activities, including atacuri ransomware and atacuri asupra site-urilor WordPress.

What is SystemBC and why is it dangerous?

SystemBC is an Remote Access Trojan (RAT) It is mainly used for:

  • Redirecting traffic through compromised systems (proxy/SOCKS5)

  • ining persistent access to the victim’s networks,

  • facilitate other attacks, including ransomware or additional malware.

The presence of SystemBC on a server is often An indicator of a much broader compromiseNot just an isolated infection.

What is this new version of Linux?

The new version of SystemBC marks a Important development:

  • It is conceived exclusiv pentru Linux

  • It is extremely Discreet and difficult to detect

  • niciunul dintre cele 62 de motoare antivirus analyzed on VirusTotal did not detect the malware at the time of discovery

  • It is mainly used in servere de hostingNot on residential networks.

This approach gives attackers IP-uri stabileIdeal for long-term operations.

Dimensiunea botnet-ului

The data analyzed shows a disturbing scale:

  • 🔢 10.340 de adrese IP distincte In a single cluster.

  • 📊 aproximativ 3.000 de IP-uri active zilnic

  • The average duration of an infection: 38 de zile

  • Some servers have been infected. peste 100 de zile

Infections are distributed globally, with most cases in:

United States, Germany, France, Singapore and India.

Affected hosting providers

Most compromised IPs belong to platforme mari de hosting, inclusiv:

  • Namecheap

  • GoDaddy

  • IONOS

  • Amazon (AWS)

  • OVH

  • Hetzner

  • DigitalOcean

This confirms that Hosting infrastructure is a priority, nu utilizatorii casnici.

Servere guvernamentale compromise

Infected servers have been identified and domenii guvernamentale, inclusiv:

  • Official website of the provincial administration of Vietnam

  • Association with the Government of Burkina Faso

These examples show that Public institutions are not immune. of such attacks.

Why is it hard to stop this malware?

Although SystemBC infrastructure suffered serious strikes in 2024 (including server and domain seizures), malware development It has not slowed..

It is constantly observed:

  • versiuni modificate,

  • cod rescris pentru evitare detectare,

  • “Bulletproof” control and control.

What does this mean for managers and companies?

🔴 Antivirusul clasic NU este suficient

🔴 Linux is not immune to malware

🔴 WordPressservers are frequent targets

Semnele unui posibil compromis includ:

  • Unusual outbound connections.

  • trafic proxy/SOCKS neautorizat,

  • persistent processes without explanation,

  • Recurring infections after “cleansing”.

Concluzia ZebraByte

This incident clearly demonstrates that:

Modern web infrastructure requires active monitoring, not just passive protection.

La ZebraByte, punem accent pe:

  • network monitoring and outbound traffic,

  • Detection of behavior,

  • Advanced protection for Linux andWordPressservers

  • Prevention, not just reaction.

If your servers or your customers nu sunt monitorizate activThere is a risk that they are already part of a botnet without you knowing it.


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert