Executive Summary
In September 2025, security researchers from Lumen Technology’s Black Lotus Labs uncovered a significant increase in the activity of the SystemBC proxy botnet, which compromised an average of 1,500 commercial virtual private servers (VPS) daily by exploiting unpatched and critically vulnerable systems. SystemBC enabled threat actors, including ransomware gangs and criminal proxy networks, to route malicious traffic through infected VPS infrastructures, obscuring command-and-control activity and facilitating large-scale cyberattacks, such as WordPress brute-forcing and malware distribution. Impacted servers often had dozens of security flaws, with infection lifespans exceeding a month and some systems exhibiting over 100 vulnerabilities.
The prevalence of SystemBC underscores a growing shift away from traditional residential botnets toward high-bandwidth, stable VPS resources easily abused due to lax patching. The incident amplifies urgent concerns around lateral movement, proxy abuse, and the need for robust network segmentation and real-time anomaly detection as attackers leverage compromised enterprise-grade infrastructure for persistent threats.
Why This Matters Now
This incident highlights how unmanaged vulnerabilities in commercial VPS environments provide attackers with scalable, long-lived botnet infrastructure for masking malicious activity. With the persistence and high data throughput of proxy botnets like SystemBC, organizations face elevated risks of data exfiltration, supply chain compromise, and compliance failures—making immediate upgrades in patch management, segmentation, and monitoring critical.
Attack Path Analysis
Attackers scanned the internet for vulnerable VPS hosts and exploited unpatched critical vulnerabilities to gain initial access. After compromising the servers, they may have attempted privilege escalation to secure persistence and full control. The malware established lateral movement by deploying SystemBC proxies and potentially enabling more threat actors to access other workloads in the same environment. SystemBC maintained persistent command and control (C2) communication via high-volume, encrypted traffic, with infected hosts acting as proxy nodes. The compromised systems facilitated exfiltration or rerouting of massive amounts of malicious traffic, enabling the proxy-as-a-service model. The overall impact was the transformation of commercial VPS infrastructure into stable, long-lived proxy highways for cybercrime and brute-forcing operations.
Kill Chain Progression
Initial Compromise
Description
Attackers identified and exploited multiple unpatched critical vulnerabilities on exposed VPS servers, deploying SystemBC malware.
Related CVEs
CVE-2021-3129
CVSS 9.8A deserialization vulnerability in Laravel Framework allows remote code execution via crafted requests.
Affected Products:
Laravel Laravel Framework – <= 8.4.2
Exploit Status:
exploited in the wildCVE-2020-14882
CVSS 9.8A remote code execution vulnerability in Oracle WebLogic Server allows unauthenticated attackers to execute arbitrary code.
Affected Products:
Oracle WebLogic Server – 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Exploit Status:
exploited in the wildCVE-2019-19781
CVSS 9.8A directory traversal vulnerability in Citrix Application Delivery Controller and Gateway allows remote code execution.
Affected Products:
Citrix Application Delivery Controller – 10.5, 11.1, 12.0, 12.1, 13.0
Citrix Gateway – 10.5, 11.1, 12.0, 12.1, 13.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Command and Scripting Interpreter
Non-Standard Port
Proxy
Application Layer Protocol
Automated Exfiltration
System Shutdown/Reboot
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Timely Patching of System Components
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Automated Asset Discovery and Vulnerability Management
Control ID: Asset Management: 1.3
NIS2 Directive – Security Requirements and Incident Handling
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
VPS infrastructure compromise creates proxy highways for malicious traffic, enabling lateral movement and data exfiltration through unpatched critical vulnerabilities in commercial systems.
Internet
SystemBC botnet hijacks internet infrastructure for cybercriminal proxy services, facilitating WordPress credential brute-forcing and command-and-control traffic obfuscation across global networks.
Computer Software/Engineering
Vulnerable software systems enable long-term infections averaging 20 unpatched vulnerabilities per host, requiring enhanced threat detection and anomaly response capabilities.
Financial Services
Proxy botnets facilitate ransomware delivery and data exfiltration attacks, demanding robust egress security policies and encrypted traffic monitoring for compliance protection.
Sources
- SystemBC malware turns infected VPS systems into proxy highwayhttps://www.bleepingcomputer.com/news/security/systembc-malware-turns-infected-vps-systems-into-proxy-highway/Verified
- SystemBC: The Malware That Turns VPS Into Cybercrime Hubshttps://blog.tecnetone.com/en-us/systembc-the-malware-that-turns-vps-into-cybercrime-hubsVerified
- SystemBC Botnet Evolves Into High-Volume VPS Proxy Network, Powering Criminal Ecosystemhttps://securityonline.info/systembc-botnet-evolves-into-high-volume-vps-proxy-network-powering-criminal-ecosystem/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF and zero trust controls such as segmentation, egress filtering, threat detection, and east-west traffic security would have prevented or significantly limited the attacker’s ability to compromise, persist, move laterally, and abuse VPS environments as proxy nodes. Microsegmentation, inline threat detection, and outbound policy enforcement are particularly relevant for stopping both propagation and abuse of compromised cloud workloads.
Control: Cloud Firewall (ACF)
Mitigation: Prevents inbound exploitation by blocking unauthorized and risky inbound connections.
Control: Threat Detection & Anomaly Response
Mitigation: Detects abnormal privilege elevation behaviors and alerts security teams.
Control: Zero Trust Segmentation
Mitigation: Restricts lateral movement by enforcing least-privilege, identity-based network access between workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized or suspicious outbound connections to known C2 infrastructure.
Control: Encrypted Traffic (HPE)
Mitigation: Monitors and secures all outbound data flows, minimizing adversary data exfiltration.
Rapidly detects compromised resources and enables incident response to isolate or remediate abused assets.
Impact at a Glance
Affected Business Functions
- Web Hosting
- E-commerce Platforms
- Online Services
Estimated downtime: 30 days
Estimated loss: $500,000
Potential exposure of sensitive customer data, including personal information and payment details, due to compromised VPS systems acting as proxies for malicious activities.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Microsegmentation: Apply zero trust segmentation and isolation to restrict workload-to-workload communication and contain initial breaches.
- • Harden Ingress/Egress: Deploy cloud-native firewalls and egress filtering to prevent exploitation and block malicious outbound C2 or proxy traffic.
- • Accelerate Threat Detection: Implement real-time anomaly detection and automated incident response to identify early signs of privilege escalation or lateral movement.
- • Secure Data in Transit: Utilize always-on high-performance encryption and inline visibility to prevent and monitor unauthorized data transfers.
- • Centralize Visibility & Policy: Leverage multicloud visibility and a unified control plane to swiftly identify, contain, and remediate compromised cloud assets.



