BillGates

Malware type
botnet, ddos, backdoor
Family
Malware family
Last IoC activity
2026-07-21 16:46:23
Profile updated
2026-07-07 14:22:05

Targeted industries: technology-and-telecommunications

Context

BillGates is a modularized malware, of supposedly Chinese origin. Its main functionality is to perform DDoS attacks, with support for DNS amplification. Often, BillGates is delivered with one or many backdoor modules. BillGates is available for *nix-based systems as well as for Windows. On Windows, the (Bill)Gates installer typically contains the various modules as linked resources.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Billgates_Auto (yara-rule)

Reports & references

  • virusbulletin.com — Kalnaihorejsi Vb2015 (report)
  • bleepingcomputer.com — Log4Shell Exploits Now Used Mostly For Ddos Botnets Cryptominers (report)
  • fortinet.com — Recent Attack Uses Vulnerability On Confluence Server (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Billgates (report)
  • thisissecurity.stormshield.com — When Elf Billgates Met Windows (report)
  • bartblaze.blogspot.com — Notes On Linuxbillgates (report)
  • akamai.com — Bill Gates Botnet Threat Advisory (report)
  • habrahabr.ru — 213973 (report)
  • Kaspersky — 64361 (report)

External references