ChinaZ is a Chinese threat actor associated primarily with distributed denial-of-service operations and multi-platform botnet activity since at least 2014. The group has targeted both Linux and Windows systems and is known for operating transient hosting infrastructure, including Chinese HFS servers, to stage malware and attack tooling. Observed intrusion activity includes SSH and Telnet brute-force attacks used to gain initial access to exposed systems, followed by downloader scripts that retrieve and execute payloads for botnet enrollment and follow-on operations. ChinaZ has been linked to Linux BillGates variants, ChinaZ.DDoSClient, and modified Gh0st RAT samples, with some Linux and Windows payloads sharing command-and-control infrastructure, indicating coordinated cross-platform botnet operations. Hosted tooling has also included Chinese-language DDoS deployment packages and Python-based scanning and flooding utilities, reflecting an operational focus on botnet propagation and attack execution. The actor’s malware ecosystem shows overlap with other Chinese malware families and tooling, including MrBlack, ServStart, and Nitol-related components, suggesting either collaboration, shared development resources, or participation in a broader Chinese underground DDoS ecosystem. The group’s demonstrated capabilities include brute-force initial access, scanning, persistence, post-compromise malware deployment, and DDoS attack execution. Although some hosted Windows malware included remote-access functionality through Gh0st RAT variants, the dominant pattern associated with ChinaZ is botnet building and denial-of-service activity rather than classic espionage. ChinaZ is best characterized as a Chinese-origin threat actor focused on offensive botnet operations and DDoS enablement across Windows and Linux environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese threat actor group conducting DDoS botnet operations targeting Windows and Linux systems, using infrastructure such as HFS servers and malware including BillGates, ChinaZ.DDoSClient, and Gh0st RAT variants.
Mentioned as an actor/group associated with ELF malware families such as Linux/ChinaZ.DDoS and Linux/Kluh.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.