More than 10,000 servers compromised with a new Linux version of SystemBC malware
A major cyber threat has recently been discovered: more than 10,000 unique IP addresses have been identified as being infected with a completely new, previously unknown variant of the virus.
O Major cyber threats It was recently discovered: over 10.000 de adrese IP unice They were identified as being infected. Completely new, previously unknown, a malware-ului SystemBCSpecially adapted for sisteme Linux.
The discovery was made by cybersecurity researchers, who identified a Massive network of compromised servers converted into proxy for criminal activities, including atacuri ransomware and atacuri asupra site-urilor WordPress.
What is SystemBC and why is it dangerous?
SystemBC is an Remote Access Trojan (RAT) It is mainly used for:
-
Redirecting traffic through compromised systems (proxy/SOCKS5)
-
ining persistent access to the victim’s networks,
-
facilitate other attacks, including ransomware or additional malware.
The presence of SystemBC on a server is often An indicator of a much broader compromiseNot just an isolated infection.
What is this new version of Linux?
The new version of SystemBC marks a Important development:
-
It is conceived exclusiv pentru Linux
-
It is extremely Discreet and difficult to detect
-
niciunul dintre cele 62 de motoare antivirus analyzed on VirusTotal did not detect the malware at the time of discovery
-
It is mainly used in servere de hostingNot on residential networks.
This approach gives attackers IP-uri stabileIdeal for long-term operations.
Dimensiunea botnet-ului
The data analyzed shows a disturbing scale:
-
🔢 10.340 de adrese IP distincte In a single cluster.
-
📊 aproximativ 3.000 de IP-uri active zilnic
-
The average duration of an infection: 38 de zile
-
Some servers have been infected. peste 100 de zile
Infections are distributed globally, with most cases in:
United States, Germany, France, Singapore and India.
Affected hosting providers
Most compromised IPs belong to platforme mari de hosting, inclusiv:
-
Namecheap
-
GoDaddy
-
IONOS
-
Amazon (AWS)
-
OVH
-
Hetzner
-
DigitalOcean
This confirms that Hosting infrastructure is a priority, nu utilizatorii casnici.
Servere guvernamentale compromise
Infected servers have been identified and domenii guvernamentale, inclusiv:
-
Official website of the provincial administration of Vietnam
-
Association with the Government of Burkina Faso
These examples show that Public institutions are not immune. of such attacks.
Why is it hard to stop this malware?
Although SystemBC infrastructure suffered serious strikes in 2024 (including server and domain seizures), malware development It has not slowed..
It is constantly observed:
-
versiuni modificate,
-
cod rescris pentru evitare detectare,
-
“Bulletproof” control and control.
What does this mean for managers and companies?
🔴 Antivirusul clasic NU este suficient
🔴 Linux is not immune to malware
🔴 WordPressservers are frequent targets
Semnele unui posibil compromis includ:
-
Unusual outbound connections.
-
trafic proxy/SOCKS neautorizat,
-
persistent processes without explanation,
-
Recurring infections after “cleansing”.
Concluzia ZebraByte
This incident clearly demonstrates that:
Modern web infrastructure requires active monitoring, not just passive protection.
La ZebraByte, punem accent pe:
-
network monitoring and outbound traffic,
-
Detection of behavior,
-
Advanced protection for Linux andWordPressservers
-
Prevention, not just reaction.
If your servers or your customers nu sunt monitorizate activThere is a risk that they are already part of a botnet without you knowing it.
ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.