Elknot is a long-running Linux-focused DDoS bot family, also referred to in some reporting as Setag, Mayday, or BillGates depending on variant and lineage. It is associated with ELF malware ecosystems targeting Linux, Unix-like systems, and embedded devices, and has been observed as one of the most prevalent malware families in that space. The family has supported multiple architectures and operating systems across variants, including Linux x86 and x86_64, Windows x86 and x64, and FreeBSD, while some reporting notes that core Elknot activity mainly targeted x86 systems.
Elknot is primarily used to build botnets for distributed denial-of-service operations. Documented attack capabilities include HTTP flood, TCP packet attacks, DNS flood, DNS amplification, ICMP flood, TCP SYN flood, and UDP flood, as well as custom DNS random-subdomain attack techniques. Variants implement command handling for starting and stopping attacks, updating modules, and executing shell commands. Some Setag-linked variants also include stronger backdoor behavior, encrypted configuration handling, and anti-analysis or anti-rival features.
The family has evolved through multiple versions. A simpler Elknot form has been described as a patcher or dropper that installs a bot and carries encrypted command-and-control configuration. Setag variants expose multiple execution modes and have been observed establishing persistence through startup scripts and runlevel links. Some samples replace common administrative utilities with copies of themselves while preserving originals elsewhere, indicating defense evasion and post-compromise control. Configuration protection has been reported using RSA-based and XOR-like schemes, while command-and-control protocol continuity across variants suggests a stable operational design despite substantial code changes.
Observed infection vectors for Elknot-associated botnets include SSH brute-force compromise and exploitation of exposed services such as MySQL and Elasticsearch. In broader Linux botnet operations, attackers have also used vulnerability scanning, brute-force tooling, and automated installation frameworks to deploy ELF DDoS malware families including Elknot. The malware has been used both directly as a bot and as a delivery component for other malware; one documented campaign used an Elknot dropper to deliver the Chalubo bot package.
Operational reporting links Elknot/BillGates activity to large-scale DDoS campaigns affecting tens of thousands of victims, with command-and-control infrastructure and victim concentration especially notable in China and the United States. Targeted sectors have included online gaming, e-commerce, online casinos, and other internet-facing services, with financial extortion assessed as a likely motive in parts of the ELF DDoS ecosystem. Elknot remains notable for its longevity, prevalence, and adaptability within Linux botnet operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
自从Log4J漏洞被曝光后... 2022年2月9日,360Netlab的蜜罐系统捕获了一个未知的ELF文件通过Log4J漏洞传播... B1txor20...目前通过Log4j漏洞传播 | 期间我们看到了Elknot,Gafgyt,Mirai等老朋友的从不缺席,也见证了一些新朋友的粉墨登场。
11 distinct techniques documented for this family, organized by ATT&CK tactic.
2 configuration encryption schemes have been found – RSA encryption – XOR like encryption
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux malware/dropper used to deliver the Chalubo package in observed attacks.
Mentioned as an established botnet family observed exploiting Log4j during the same period; no further analysis in this article.
Mentioned only as an example of botnets previously hosted on abused HFS panels.
A long-running DDoS bot family written in C++, mainly targeting x86 platforms and supporting multiple DDoS attack methods including HTTP flood, DNS flood, DNS amplification, ICMP flood, TCP SYN flood, UDP flood, and TCP-based DNS attacks. The malware uses a C2 protocol with REGISTER, attack, configuration, module update, and shell command capabilities, and has been observed attacking DNS root name servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.