The Containment Era is here. →Explore

Executive Summary

In mid-2025, cybersecurity researchers from Lumen's Black Lotus Labs identified a large-scale proxy botnet operation named REM Proxy, powered primarily by the SystemBC malware. Attackers leveraged SystemBC to compromise over 1,500 virtual private servers (VPS) daily, utilizing them to fuel a criminal proxy-as-a-service spanning 80 command-and-control (C2) servers. The network enabled threat actors to anonymize malicious activities and included access to approximately 20,000 vulnerable Mikrotik routers and additional open proxies. This infrastructure facilitated evasion, lateral movement, and widespread malicious activity with significant security implications for targeted and intermediary organizations.

This incident underscores the ongoing evolution of proxy botnets and malware-as-a-service ecosystems, which pose critical risks for organizations across various sectors. As the boundaries between cybercrime infrastructure and legitimate cloud assets blur, defenders must place renewed emphasis on advanced threat detection, network segmentation, and zero trust principles to mitigate similar emergent threats.

Why This Matters Now

The rise of SystemBC-powered REM Proxy highlights an urgent risk: threat actors seamlessly co-opting cloud resources for persistent botnet operations and anonymization. This trend amplifies attackers’ reach and stealth, making traditional detection and perimeter defenses increasingly inadequate. Organizations must act now to secure hybrid environments and address both east-west and egress network threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

This incident exposed weaknesses relevant to NIST 800-53, HIPAA, PCI DSS, and Zero Trust frameworks, particularly around encrypted traffic, network segmentation, and threat detection controls.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust Segmentation, east-west traffic controls, and robust egress policy enforcement would have contained SystemBC propagation, blocked unauthorized outbound C2 flows, and detected anomalous proxy activity, thereby disrupting nearly every stage of the attack.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked inbound exploitation attempts targeting exposed network devices.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevented escalation of privileges through least-privilege policy and isolation of sensitive devices.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked unauthorized internal communications that facilitate malware propagation.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Blocked unauthorized outbound C2 traffic and domain-based connections.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Detected and secured sensitive data flows, reducing the risk of data interception during exfiltration.

Impact (Mitigations)

Enabled rapid detection and response to anomalous proxy and botnet traffic.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • IT Security
  • Customer Data Management
Operational Disruption

Estimated downtime: 30 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive customer data due to compromised servers acting as proxies for malicious activities.

Recommended Actions

  • Deploy and enforce Cloud Firewall (ACF) to limit exposure of devices and block exploit attempts.
  • Implement Zero Trust Segmentation and microsegmentation to minimize lateral movement between workloads and devices.
  • Apply strict egress filtering and FQDN-based outbound controls to disrupt unauthorized C2 and proxy activity.
  • Enable high-performance encryption for all east-west and outbound data to secure exfiltration pathways.
  • Leverage advanced threat detection and anomaly response tooling to rapidly identify and remediate botnet or proxy-based compromises.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image