Several recent ransomware attacks have used SystemBC malware variant called SystemBC as a backdoor. SystemBC works as a network proxy for remote access Trojan, or RAT, that allows threat actors to deploy additional commands and scripts to infected Windows devices and to gather data. Ryuk and Egregor attacks have been tied to more than 70 attacks worldwide since September, with the majority taking place within the U.S., a security firm Digital Shadows reports. The security firm Intel notes that one-third of all ransomware attacks over the last 12 months have been linked to the attacks.”]
Source: https://www.govinfosecurity.com/ransomware-operators-using-systembc-malware-as-backdoor-a-15612