Last seven days
- First activity
- Sep 5, 2026
- Last activity
- Sep 5, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
BillGates, also known as Linux/BillGates, is a Linux-focused DDoS botnet with limited backdoor and rootkit functionality.
Profile source: Mallory opens in a new tabBillGates
BillGates, also known as Linux/BillGates, is a Linux-focused DDoS botnet with limited backdoor and rootkit functionality. It uses command-and-control communications to receive attack instructions, execute remote shell commands, update or download components, and collect host status information. Documented attack functionality includes TCP, UDP, ICMP, HTTP, DNS flood, and DNS amplification attacks. Variants use modular designs that separate control and attack functions, and can maintain lists of DNS resolvers for reflection/amplification activity.
BillGates establishes persistence through init scripts, runlevel entries, cron jobs, watchdog processes, and component reinstallation. It can evade detection by daemonizing, redirecting standard streams, replacing or aliasing common system-monitoring utilities, hiding its processes or artifacts, and removing competing malware. It has been associated with ChinaZ activity and has also been deployed following exploitation of exposed server-side vulnerabilities, including Log4Shell and Atlassian Confluence vulnerabilities. Observed ChinaZ campaigns also used SSH and Telnet credential brute forcing to compromise Linux hosts and deploy BillGates.
Samples
Reported operators
In the last few months we have observed a higher volume of attacks from Billgates, a DDoS botnet attributed to ChinaZ.
Exploited software
MITRE ATT&CK
Reporting
The Rocke Group deployed Pro-Ocean, a cloud-focused cryptojacking malware family designed to mine Monero while improving stealth, persistence, and worm-like propagation across compromised environments. Palo Alto Networks Unit 42 reported that the malware targets vulnerable services including Apache ActiveMQ via CVE-2016-3088, Oracle WebLogic via CVE-2017-10271, and unsecured Redis instances, with notable focus on Alibaba Cloud and Tencent Cloud deployments. Written in Go, Pro-Ocean hides an embedded XMRig miner behind multiple obfuscation layers and organizes its activity into four modules: hiding, mining, infecting, and watchdog. The malware’s hiding module abuses LD_PRELOAD and /etc/ld.so.preload to conceal files and processes, while the infection module scans local subnets and uses public exploits to spread laterally. Its installation routine removes competing malware and miners, disables iptables, attempts SSH-key-based movement between systems, and uninstalls cloud monitoring agents associated with Tencent Cloud and Alibaba Cloud. A watchdog component maintains persistence and kills high-CPU processes so the miner can maximize resource consumption on infected hosts.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.