Researchers documented BillGates as a Linux malware family built primarily for distributed denial-of-service attacks, with variants capable of launching TCP, UDP, ICMP, HTTP, DNS flood, and DNS amplification campaigns. Analyses of multiple samples showed a modular design, command-and-control communications, and persistence through cron jobs and init scripts, while newer variants added stronger process monitoring and self-reinstallation behavior. Beyond DDoS activity, the malware also provided limited backdoor and rootkit functionality, including remote command execution, component updates, and the ability to download additional payloads.
Subsequent reporting tied BillGates to the broader ChinaZ threat ecosystem, where investigators observed the malware deployed alongside Windows-based tools including Gh0st RAT variants and a DDoS client, suggesting a unified botnet spanning Linux and Windows hosts. Researchers linked the activity through shared infrastructure, honeypot observations, and hosted attack tooling, while defenders were advised to hunt for filesystem artifacts, lock files, startup entries, altered system binaries, and cron-based persistence, then remove malicious processes, restore legitimate utilities, scan for follow-on malware, and rotate credentials after cleanup.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
Intezer published research linking ChinaZ to BillGates, Gh0st RAT variants, ChinaZ.DDoSClient, and related tooling hosted on Chinese HFS servers. The report also noted overlaps with Nitol, ServStart, MrBlack, and a Gh0st RAT RC4 key previously seen in Iron Tiger's Operation PZCHAO.
Bart Blaze published a practical overview of Linux/BillGates describing its DDoS, rootkit, and backdoor capabilities along with filesystem artifacts, persistence locations, and cleanup steps. The post highlighted indicators such as /etc/cmd.n, /etc/conf.n, /etc/init.d/DbSecuritySpt, lock files in /tmp, and replaced system utilities.
MalwareMustDie published research on a new ChinaZ-linked malware variant named ELF Linux/BillGates.Lite. The report indicates continued development of the BillGates malware family beyond earlier documented variants.
The Intezer report states that ChinaZ, a Chinese threat actor, has been deploying DDoS botnets since at least November 2014. The group targeted both Linux and Windows systems.
A Russian IT website published an article in February 2014 describing the BillGates Linux botnet as a Trojan with versatile DDoS functionality. This is the earliest dated public reference to the malware in the provided sources.
Investigators used the shared C2 domain ak-74.top with RiskIQ and Shodan to identify additional ChinaZ-linked HFS servers. Those servers hosted more Windows malware plus a 7z archive containing Python-based port scanning and DDoS tooling.
After one day, the same ChinaZ HFS panel was updated with two ChinaZ.DDoSClient samples compiled for x86 and x86_64 systems. This showed active refresh of hosted malware on the operational server.
Researchers found a transient Chinese HFS server hosting Linux BillGates binaries and a Windows Gh0st RAT sample named BX.exe. The BillGates and Gh0st RAT samples decoded to the same command-and-control address, indicating a unified botnet targeting Linux and Windows systems.
Intezer researchers reported increased attack volume from BillGates attributed to ChinaZ. They observed intrusions using SSH and Telnet brute-force attacks followed by a bash downloader that executed implants from /root or /tmp.
Securelist analyzed BillGates samples detected as Backdoor.Linux.Mayday.f and Backdoor.Linux.Ganiw.a, documenting modular Linux DDoS malware with cron and init-script persistence, C2 communications, and multiple flood capabilities. The analysis covered simpler atddd-family samples and the more advanced cupsdd/cupsddh pair.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourcebartblaze.blogspot.com
Open sourceblog.malwaremustdie.org
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.