Elknot, also known as BillGates, is a long-running C++ DDoS botnet family. Two major versions have been documented: an earlier Elknot/Mayday variant and a later BillGates variant. It targets primarily x86 systems and has supported Windows x86/x64, Linux x86/x64, and FreeBSD; Linux-focused variants have also been prevalent among ELF malware. Elknot/BillGates supports HTTP flooding, TCP packet and SYN flooding, UDP and ICMP flooding, DNS flooding, DNS amplification, and DNS random-subdomain attacks. Its command-and-control protocol supports attack control, configuration changes, module updates, and remote shell-command execution. Configuration data may be protected with RSA or XOR-like schemes. Infection activity has been observed through SSH credential attacks and exploitation of exposed MySQL and Elasticsearch services, and the family was also observed exploiting Log4j2 on Linux and Windows. Elknot droppers have additionally been used to deliver the Chalubo DDoS botnet package. The botnet has been associated with large-scale attacks against online gaming, e-commerce, online casino, cloud, and DNS-related infrastructure, with activity heavily affecting targets in China and other countries. Some Setag-related variants establish persistence, replace administrative utilities to conceal activity, and store DNS-amplification infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
自从Log4J漏洞被曝光后... 2022年2月9日,360Netlab的蜜罐系统捕获了一个未知的ELF文件通过Log4J漏洞传播... B1txor20...目前通过Log4j漏洞传播 | 期间我们看到了Elknot,Gafgyt,Mirai等老朋友的从不缺席,也见证了一些新朋友的粉墨登场。
12 distinct techniques documented for this family, organized by ATT&CK tactic.
2 configuration encryption schemes have been found – RSA encryption – XOR like encryption
The bot then establishes communication with its C&C server. The initial packet contains the memory and CPU statistics of the compromised machine.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux malware/dropper used to deliver the Chalubo package in observed attacks.
Mentioned as an established botnet family observed exploiting Log4j during the same period; no further analysis in this article.
A long-running DDoS botnet active on Linux and later ported to Windows. Samples exploiting the Log4j2 vulnerability were observed for both platforms and shared C2 infrastructure.
Mentioned only as an example of botnets previously hosted on abused HFS panels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.