BillGates is a Linux-focused botnet malware family primarily used to conduct distributed denial-of-service attacks. It has been documented as a multi-component Linux backdoor with modular variants that support several flooding techniques, including TCP, UDP, ICMP, HTTP, DNS flood, and DNS amplification attacks. Some variants separate control and attack functionality into distinct components and maintain local coordination between modules, while later versions add watchdog and reinstallation logic to improve resilience on compromised hosts.
Beyond DDoS activity, BillGates has limited backdoor and rootkit-like functionality. Documented capabilities include execution of remote shell commands, downloading or updating additional components, and hiding its presence by replacing common system utilities used for process and network inspection. It gathers host profiling data such as operating system and CPU information before communicating with command infrastructure, and some variants maintain configuration data used to control attacks and updates.
Persistence is commonly achieved through init scripts, runlevel symlinks, and cron-based mechanisms. Operational maintenance routines have included killing competing malware or processes, relaunching missing components, re-downloading implants, and clearing logs or shell history. Certain variants also use lock files and watchdog processes to ensure only one active instance runs and to restart components if they are terminated.
BillGates has been associated with Chinese threat activity and has been attributed in some reporting to the ChinaZ ecosystem. It has also appeared in opportunistic exploitation campaigns in which vulnerable internet-facing services were used to deploy Linux malware, including activity exploiting Log4Shell and Oracle WebLogic flaws. BillGates has been observed alongside other DDoS and cryptomining malware families in shared operational environments, reflecting its use both as a standalone Linux botnet and as one payload among broader post-exploitation toolsets.
The malware targets Linux systems, including internet-exposed servers, and is notable for combining mature DDoS functionality with lightweight backdoor behavior and durable persistence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In August 2021, Atlassian published a security advisory about CVE-2021-26084 that could enable a threat actor to run arbitrary code on unpatched Confluence Server and Data Center instances. After releasing the advisory, there occur massive scanning and proof-of-concept exploit code in public. We also collect a lot attacking traffic.
In December 2021, researchers found Log4j version 2.14.1 and all previous versions to be vulnerable to CVE-2021-44228, dubbed "Log4Shell," a critical zero-day remote code execution flaw. | Other payloads seen dropped by recent Log4j exploitation include: BillGates malware (DDoS)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the last few months we have observed a higher volume of attacks from Billgates, a DDoS botnet attributed to ChinaZ.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, check for any potentially created jobs by looking in: /etc/cron.X where X is a name or folder, for example /etc/cron.daily. You may also wish to look in: /var/spool/cron/
CThreadLoopCmd reads commands from g_cmdDoing (the file cmd.n) and executes them using the call system(cmd).
2 configuration encryption schemes have been found – RSA encryption – XOR like encryption
Both of these instances share the same CNC domain... Since both BillGates and the Gh0st RAT instances found in the initially discovered HFS panel shared the same CNC, we can associate both implants to be components of a single botnet.
CThreadConnSender reads commands from the queue and passes them to the cupsddh module via a TCP connection with 127.0.0.1 on port 10808.
Attempt to remove other malware and miners including Luoxk, BillGates, XMRig, Hashfish and more... Once found, it kills them. ... This script loops forever and searches for processes that utilize more than 30% of the CPU... Once found, it kills them.
BillGates is malware designed primarily for Linux, and since it is a botnet, it is mostly used for DDoS purposes.
This means that 5 attack types are possible: 0x80 – TCP flood... 0x81 – UDP flood... 0x82 – ICMP flood... 0x83, 0x84 – two DNS flood attacks.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux DDoS malware family that the same attacker later attempted to retrieve; mentioned as possibly linked by some researchers to Elknot authors.
Referenced as a known botnet/toolset used for comparison against Kaiji's custom-built implant.
BillGates is a botnet malware family that targets Linux systems, primarily used for launching DDoS attacks and sometimes for cryptocurrency mining.
BillGates is a botnet malware family that targets Linux systems, enabling DDoS attacks and remote control of infected machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.