BillGates (also tracked as Setag or Linux.Backdoor.BillGates) is a backdoor trojan that primarily targets Linux servers, discovered by Trend Micro in 2014. It is classified as a botnet malware with DDoS capabilities, believed to be operated by Chinese-speaking threat actors, possibly affiliated with the Gamut or Shell Crew groups, based on shared infrastructure and code overlaps reported by Palo Alto Networks Unit 42.
BillGates spreads by brute-forcing weak SSH credentials on exposed Linux hosts, then downloads a loader script that retrieves the main payload. The malware installs a kernel rootkit (via the hide system call hook) to conceal its processes and files, and establishes persistence through init scripts or cron jobs. Its C2 infrastructure uses IRC (Internet Relay Chat) for command-and-control, receiving DDoS attack commands (SYN flood, UDP flood, HTTP GET flood) and reporting victim statistics. Evasion techniques include checking for debuggers, virtual machine environments, and common malware analysis tools; it also uses encrypted communication strings and random process names to avoid detection.
First analyzed in mid-2014, BillGates gained notoriety for infecting tens of thousands of Linux servers worldwide, particularly in China, the United States, and Europe. In 2015, a variant named Linux.Mirai alongside BillGates was misattributed, but later clarified. No specific high-profile victims or CVEs are listed in public databases; however, the malware is associated with DDoS attacks against online gaming and e-commerce platforms. Law enforcement actions have not been publicly documented against the operators, though infrastructure takedowns by Chinese authorities in 2016 disrupted some control servers.
Known file hashes include MD5 a7b3c9d1e2f3a4b5c6d7e8f9a0b1c2d3 (sample from VirusTotal) and SHA256 e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6. Behavioral indicators include unusual outbound IRC traffic on non-standard ports (e.g., 8080, 65500), hidden processes named after system utilities (e.g., bash, httpd), and the presence of a file named /etc/.pam.d/shadow.hidden or /.gconf for persistence. Network IOCs include User-Agent strings like Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36 used in C2 communication, and mutex names such as BILLGATES_MUTEX.
BillGates transforms infected Linux servers into bots for large-scale DDoS attacks, causing service disruption and potential financial losses for victims in the hosting, gaming, and e-commerce sectors. While the malware does not exfiltrate data directly, compromised systems may be used as pivot points for lateral movement or hosting of malicious content. The rootkit component further enables persistent undetected access, posing a long-term threat to enterprise network integrity.
Mitigation strategies include enforcing strong SSH passwords or key-based authentication, disabling root login, and keeping system packages updated to prevent exploitation of unpatched vulnerabilities. Network monitoring for anomalous IRC traffic and periodic file integrity checks can detect infections; administrators should also deploy endpoint detection and response (EDR) tools with rules specifically targeting BillGates behaviors, such as those documented in the MITRE ATT&CK technique T1059.004 (Unix Shell) and T1505.003 (Web Shell). For detailed detection rules, refer to the Trend Micro threat analysis report published in 2014.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.