Over 10,000 Linux Servers Infected by SystemBC Botnet Variant
First seen 4 Feb 2026, 20:59 UTC
•



+1
•30.6
Export
Article Content
Browse articles
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting government websites and are being exploited for cybercrime activities. Despite previous disruptions to its infrastructure in May 2024, SystemBC remains active and continues to function as a multi-platform proxy for malicious traffic.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
New PoC Exploit for NTLM Reflection Bypass Vulnerability on Windows Server
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
AI-Driven Cyber Threats Escalate: Five Eyes Warn of Open Weight Model Risks