BlueVoyant A.I CyberSecurity Scoring
BlueVoyant
Company Information
Website:https://www.bluevoyant.com/
Employees number:636
Number of followers:125,350
NAICS:541514
Industry Type:Computer and Network Security
Homepage:bluevoyant.com
BlueVoyant Risk Score (AI oriented)
Between 650 and 699
BlueVoyantComputer and Network Security
Updated:
30/06/2026
30/06/2026
699/1000
Weak
B
BlueVoyant Global Score (TPRM)
xxxx
BlueVoyantComputer and Network Security
Score locked

BlueVoyantWeak
Current Score
699B (WEAK)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
702
AUGUST 2026
701
JULY 2026
699
JUNE 2026
699
MAY 2026
697
APRIL 2026
697
MARCH 2026
695
FEBRUARY 2026
694
JANUARY 2026
693
DECEMBER 2025
692
NOVEMBER 2025
690
OCTOBER 2025
689
OCTOBER 2022
724
Ransomware
01 Oct 2022 • BlueVoyant
BlueVoyant
Supply Chain Cyber Incidents
601
CRITICAL-123
BLU909050624
BlueVoyant's research revealed a significant concern surrounding supply chain cyber incidents, with 98% of surveyed companies acknowledging the impact these incidents have on their operations. The increasing trend of outsourcing escalates the risk to sensitive data and operations due to cyber threats associated with third parties. Supply chain vulnerabilities can lead to severe damage or loss within minutes, highlighting the critical nature of monitoring and addressing such risks proactively. BlueVoyant's focus on managing external cyber risks aims to safeguard companies against these looming threats by offering specialized cybersecurity solutions.
INCIDENT DETAILS -
TYPE
REFERENCES
JANUARY 2018
758
Ransomware
01 Jan 2018 • BlueVoyant
Ryuk, Rhysida, Conti and Play: SystemBC Malware Turns Windows Machines Into SOCKS5 Proxies for Ransomware Attacks
SystemBC Malware: A Persistent Proxy and RAT Tool in Ransomware Attacks
650
CRITICAL-108
BLUCONPLARYU1782822739
SystemBC Malware: A Persistent Proxy and RAT Tool in Ransomware Attacks
SystemBC, also known as Coroxy, is a long-standing Windows malware family first detected in exploit kits around 2018–2019. Initially a secondary payload, it has since evolved into a widely used commodity tool, frequently deployed alongside loaders like Buer, QBot, and Emotet. Its lightweight, modular design and dual functionality as both a SOCKS5 proxy and remote-access trojan (RAT) make it a favored component in ransomware operations, including those linked to Ryuk, Conti, Egregor, BlackBasta, Play, and Rhysida.
The malware follows a predictable infection lifecycle: after initial access, it copies itself into a randomly named file under `%ProgramData%`, establishes persistence via a registry Run key and scheduled task, and employs anti-detection measures such as skipping installation if security software like Emsisoft’s a2guard.exe is detected. Some variants use in-memory droppers to unpack secondary binaries, either injecting them into processes or executing them from disk.
SystemBC’s defining feature is its SOCKS5 proxy capability, which allows attackers to route command-and-control (C2) and exfiltration traffic through compromised hosts. Newer versions increasingly use Tor for anonymity, blending malicious traffic with legitimate enterprise flows to evade detection. Operators manage live SOCKS sessions via a control panel that supports auto-updates, authentication, and tens of thousands of simultaneous connections.
Early versions relied on encrypted beacons (RC4-encrypted host/user data) for C2 communication, while newer builds shift traffic to Tor using embedded directory-authority IPs. The malware supports a range of payloads EXE, DLL, shellcode, VBS, BAT, CMD, and PowerShell many executed in memory to avoid disk writes.
For threat actors, SystemBC is rarely the end goal but a force multiplier, enabling stealthy lateral movement and tool reuse across access-as-a-service chains. Its presence often signals broader compromise, including credential theft and further malware deployment. Defenders are advised to monitor unusual outbound SOCKS/Tor connections, suspicious scheduled tasks, and in-memory execution techniques, while network segmentation and egress filtering can limit its impact.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for BlueVoyant ??
What was BlueVoyant's A.I Rankiteo Cyber Score in August 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in July 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in June 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in May 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in April 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in March 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in February 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in January 2026 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in December 2025 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in November 2025 ??
What was BlueVoyant's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on BlueVoyant's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with BlueVoyant ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view BlueVoyant's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?