Executive Summary
In mid-2025, cybersecurity researchers from Lumen's Black Lotus Labs identified a large-scale proxy botnet operation named REM Proxy, powered primarily by the SystemBC malware. Attackers leveraged SystemBC to compromise over 1,500 virtual private servers (VPS) daily, utilizing them to fuel a criminal proxy-as-a-service spanning 80 command-and-control (C2) servers. The network enabled threat actors to anonymize malicious activities and included access to approximately 20,000 vulnerable Mikrotik routers and additional open proxies. This infrastructure facilitated evasion, lateral movement, and widespread malicious activity with significant security implications for targeted and intermediary organizations.
This incident underscores the ongoing evolution of proxy botnets and malware-as-a-service ecosystems, which pose critical risks for organizations across various sectors. As the boundaries between cybercrime infrastructure and legitimate cloud assets blur, defenders must place renewed emphasis on advanced threat detection, network segmentation, and zero trust principles to mitigate similar emergent threats.
Why This Matters Now
The rise of SystemBC-powered REM Proxy highlights an urgent risk: threat actors seamlessly co-opting cloud resources for persistent botnet operations and anonymization. This trend amplifies attackers’ reach and stealth, making traditional detection and perimeter defenses increasingly inadequate. Organizations must act now to secure hybrid environments and address both east-west and egress network threats.
Attack Path Analysis
Attackers initiated compromise by distributing SystemBC malware through exploited routers and open proxies, building a large botnet. Privilege escalation likely occurred as malware gained higher access on infected devices. Lateral movement facilitated the spread between network devices and workloads, expanding botnet control. SystemBC established persistent encrypted command and control channels to numerous C2 servers. The botnet was then leveraged to proxy malicious traffic and exfiltrate data via covert channels. The ultimate impact included loss of network integrity and widespread abuse of resources for proxying, impacting operational security.
Kill Chain Progression
Initial Compromise
Description
SystemBC malware compromised internet-facing Mikrotik routers and open proxies, enrolling them into the REM Proxy botnet.
Related CVEs
CVE-2021-44228
CVSS 10Apache Log4j2 Remote Code Execution Vulnerability (Log4Shell) allows unauthenticated remote attackers to execute arbitrary code on affected systems.
Affected Products:
Apache Log4j2 – 2.0-beta9 to 2.14.1
Exploit Status:
exploited in the wildCVE-2019-11510
CVSS 10Pulse Connect Secure Arbitrary File Disclosure Vulnerability allows unauthenticated remote attackers to read arbitrary files, including credentials.
Affected Products:
Pulse Secure Pulse Connect Secure – 8.1R1 to 8.1R15.1, 8.2R1 to 8.2R12, 8.3R1 to 8.3R7, 8.3R1 to 8.3R7, 9.0R1 to 9.0R3.3
Exploit Status:
exploited in the wildCVE-2018-13379
CVSS 9.8Fortinet FortiOS SSL VPN Web Portal Path Traversal allows unauthenticated attackers to download system files via crafted HTTP resource requests.
Affected Products:
Fortinet FortiOS – 5.6.3 to 5.6.7, 6.0.0 to 6.0.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Proxy
Application Layer Protocol
System Services: Service Execution
Command and Scripting Interpreter
Valid Accounts
Create or Modify System Process
Data Encoding
User Execution
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Intrusion-Detection and Monitoring
Control ID: 11.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 9(2)
CISA ZTMM 2.0 – Isolate critical assets & monitor east-west traffic
Control ID: Network and Environment Segmentation
NIS2 Directive – Incident Management Capabilities
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
SystemBC botnet's 1,500 daily VPS victims and proxy network pose critical risks to encrypted traffic, east-west segmentation, and compliance frameworks including PCI requirements.
Health Care / Life Sciences
REM Proxy's 20,000 compromised Mikrotik routers threaten HIPAA compliance through lateral movement attacks and data exfiltration via unencrypted traffic vulnerabilities.
Telecommunications
Botnet's 80 C2 servers exploiting network infrastructure creates egress security failures, threatening multicloud visibility and zero trust segmentation for telecom operators.
Information Technology/IT
SystemBC malware targeting VPS infrastructure directly impacts IT service providers' Kubernetes security, cloud firewall defenses, and threat detection capabilities across hybrid environments.
Sources
- SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servershttps://thehackernews.com/2025/09/systembc-powers-rem-proxy-with-1500.htmlVerified
- VPS servers hijacked into malware proxies - here's how to stay safehttps://www.techradar.com/pro/security/vps-servers-hijacked-into-malware-proxies-heres-how-to-stay-safeVerified
- SystemBC malware turns vulnerable VPS into proxies – HackMaghttps://hackmag.com/news/systembcVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust Segmentation, east-west traffic controls, and robust egress policy enforcement would have contained SystemBC propagation, blocked unauthorized outbound C2 flows, and detected anomalous proxy activity, thereby disrupting nearly every stage of the attack.
Control: Cloud Firewall (ACF)
Mitigation: Blocked inbound exploitation attempts targeting exposed network devices.
Control: Zero Trust Segmentation
Mitigation: Prevented escalation of privileges through least-privilege policy and isolation of sensitive devices.
Control: East-West Traffic Security
Mitigation: Blocked unauthorized internal communications that facilitate malware propagation.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked unauthorized outbound C2 traffic and domain-based connections.
Control: Encrypted Traffic (HPE)
Mitigation: Detected and secured sensitive data flows, reducing the risk of data interception during exfiltration.
Enabled rapid detection and response to anomalous proxy and botnet traffic.
Impact at a Glance
Affected Business Functions
- Network Operations
- IT Security
- Customer Data Management
Estimated downtime: 30 days
Estimated loss: $500,000
Potential exposure of sensitive customer data due to compromised servers acting as proxies for malicious activities.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy and enforce Cloud Firewall (ACF) to limit exposure of devices and block exploit attempts.
- • Implement Zero Trust Segmentation and microsegmentation to minimize lateral movement between workloads and devices.
- • Apply strict egress filtering and FQDN-based outbound controls to disrupt unauthorized C2 and proxy activity.
- • Enable high-performance encryption for all east-west and outbound data to secure exfiltration pathways.
- • Leverage advanced threat detection and anomaly response tooling to rapidly identify and remediate botnet or proxy-based compromises.



