BillGates
- Malware type
- botnet, ddos, backdoor
- Family
- Malware family
- Last IoC activity
- 2026-07-21 16:46:23
- Profile updated
- 2026-07-07 14:22:05
Targeted industries: technology-and-telecommunications
Context
BillGates is a modularized malware, of supposedly Chinese origin. Its main functionality is to perform DDoS attacks, with support for DNS amplification. Often, BillGates is delivered with one or many backdoor modules. BillGates is available for *nix-based systems as well as for Windows. On Windows, the (Bill)Gates installer typically contains the various modules as linked resources.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Billgates_Auto (yara-rule)
Reports & references
- virusbulletin.com — Kalnaihorejsi Vb2015 (report)
- bleepingcomputer.com — Log4Shell Exploits Now Used Mostly For Ddos Botnets Cryptominers (report)
- fortinet.com — Recent Attack Uses Vulnerability On Confluence Server (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Billgates (report)
- thisissecurity.stormshield.com — When Elf Billgates Met Windows (report)
- bartblaze.blogspot.com — Notes On Linuxbillgates (report)
- akamai.com — Bill Gates Botnet Threat Advisory (report)
- habrahabr.ru — 213973 (report)
- Kaspersky — 64361 (report)