SystemBC C2 Server Reveals 1570+ Victims in The Gentlemen Ransomware Operation
Threat actors connected to the Gentlemen ransomware-as-a-service (RaaS) operation have been seen trying to install SystemBC, a known proxy virus.
A botnet with over 1,570 victims has been found thanks to the command-and-control (C2 or C&C) server connected to SystemBC, according to recent research released by Check Point.
According to Check Point, SystemBC creates SOCKS5 network tunnels inside the victim's environment and uses a unique RC4-encrypted protocol to connect to its C&C server. Additionally, it has the ability to download and run other malware, with payloads that are either written to disk or injected straight into memory.
The Gentlemen is one of the most active ransomware organizations, having claimed over 320 victims on its data leak site since it first appear...

