The Gentlemen ransomware expands operations with SystemBC Proxy malware
SystemBC is a malware tool used to establish covert communications and maintain persistence inside compromised networks.
Acting as a negotiator for five victim organizations, Angelo Martino shared sensitive details with BlackCat operators, allowing them to extract higher ransom payments.
SystemBC is a malware tool used to establish covert communications and maintain persistence inside compromised networks.
The attackers exploited vulnerabilities in the systemu2019s cross-chain verification layer, known as the Decentralized Verifier Network (DVN).
The US-based firm said the entry point was the compromised Context.ai tool used by an employee.
The technique exploits the .NET AppDomainManager mechanism, allowing attackers to run malicious code inside a trusted process.
Authorities allege he led a ransomware operation that breached corporate servers, encrypted sensitive data, and demanded Bitcoin payments.
The attacker posed as an external IT support worker using a fake Microsoft 365 domain designed to appear legitimate.