BillGates is a Linux botnet malware family that has been observed in opportunistic exploitation activity against internet-exposed servers. It is commonly associated with botnet operations targeting known vulnerabilities in public-facing applications and services, including campaigns exploiting Atlassian Confluence Server vulnerability CVE-2021-26084. In observed activity, BillGates appeared alongside other botnet and cryptomining malware families such as Muhstik, Kinsing, Dofloo, and Enemybot, indicating its use in broad exploitation ecosystems that rapidly weaponize newly disclosed or routinely exploited flaws. BillGates is primarily known as a botnet payload rather than a ransomware or espionage platform. The available evidence in this context supports its use for initial compromise of vulnerable systems and post-compromise botnet deployment, but does not directly establish specific extortion tactics, nation-state sponsorship, or a definitive country of origin. High-confidence reporting here ties BillGates to exploitation of widely abused server-side vulnerabilities, but does not provide corroborated detail on distinct sub-groups, victimology by country, or sector-specific targeting attributable uniquely to this malware family.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BillGates is a botnet that exploited several of the top twelve most exploited vulnerabilities in 2022, used for DDoS attacks and botnet propagation.
Referenced as another identified payload associated with exploitation attempts against CVE-2021-26084.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.