Skip to content

BillGates

BillGates, also known as Linux/BillGates, is a Linux-focused DDoS botnet with limited backdoor and rootkit functionality.

Profile source: Mallory opens in a new tab

BillGates

Family profile

BillGates, also known as Linux/BillGates, is a Linux-focused DDoS botnet with limited backdoor and rootkit functionality. It uses command-and-control communications to receive attack instructions, execute remote shell commands, update or download components, and collect host status information. Documented attack functionality includes TCP, UDP, ICMP, HTTP, DNS flood, and DNS amplification attacks. Variants use modular designs that separate control and attack functions, and can maintain lists of DNS resolvers for reflection/amplification activity.

BillGates establishes persistence through init scripts, runlevel entries, cron jobs, watchdog processes, and component reinstallation. It can evade detection by daemonizing, redirecting standard streams, replacing or aliasing common system-monitoring utilities, hiding its processes or artifacts, and removing competing malware. It has been associated with ChinaZ activity and has also been deployed following exploitation of exposed server-side vulnerabilities, including Log4Shell and Atlassian Confluence vulnerabilities. Observed ChinaZ campaigns also used SSH and Telnet credential brute forcing to compromise Linux hosts and deploy BillGates.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Persistence
  • Post Exploitation

Observed infrastructure

Last seven days

First activity
Sep 5, 2026
Last activity
Sep 5, 2026
Feed role
Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • FR1

Leading providers

  • 12651980 CANADA INC.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
ChinaZ

In the last few months we have observed a higher volume of attacks from Billgates, a DDoS botnet attributed to ChinaZ.

Exploited software

Vulnerabilities linked to BillGates

2 CVEs

MITRE ATT&CK

BillGates in ATT&CK

24 distinct techniques

Reporting

Research mentioning BillGates

Jan 1
Intezer

Rocke Group Targets the Cloud: Wants Your SSH Keys - Intezer

The Rocke Group deployed Pro-Ocean, a cloud-focused cryptojacking malware family designed to mine Monero while improving stealth, persistence, and worm-like propagation across compromised environments. Palo Alto Networks Unit 42 reported that the malware targets vulnerable services including Apache ActiveMQ via CVE-2016-3088, Oracle WebLogic via CVE-2017-10271, and unsecured Redis instances, with notable focus on Alibaba Cloud and Tencent Cloud deployments. Written in Go, Pro-Ocean hides an embedded XMRig miner behind multiple obfuscation layers and organizes its activity into four modules: hiding, mining, infecting, and watchdog. The malware’s hiding module abuses LD_PRELOAD and /etc/ld.so.preload to conceal files and processes, while the infection module scans local subnets and uses public exploits to spread laterally. Its installation routine removes competing malware and miners, disables iptables, attempts SSH-key-based movement between systems, and uninstalls cloud monitoring agents associated with Tencent Cloud and Alibaba Cloud. A watchdog component maintains persistence and kills high-CPU processes so the miner can maximize resource consumption on infected hosts.

Jan 28
Palo Alto Networks Unit 42

Pro-Ocean: Rocke Group’s New Cryptojacking Malware

May 28
Fortinet Threat Research

New Rocke Variant Ready to Box Any Mining Challengers

Aug 30
Talos Intelligence

Rocke: The Champion of Monero Miners

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.