logo

Notes on Linux/BillGates

ID: db566da6-0d77-5d75-8efb-744a3b615084

STIX ID: report--db566da6-0d77-5d75-8efb-744a3b615084

Feed Name: Blaze's Security Blog

Threat Score
55/100

Date Published: 2017-12-03

Date Updated: 2026-04-19

Author: Bart

...
...

This post provides practical notes on the Linux/BillGates botnet, a Linux-focused DDoS malware with limited backdoor/rootkit capabilities. It lists key artefacts and indicators (e.g., files under /etc, /tmp, /usr/bin/bsd-port, and libamplify.so), identifies typical DDoS module names (atddd, cupsdd[h], ksapdd/kysapdd, sksapdd/skysapdd), and describes how it replaces system tools (ps, netstat, lsof, ss) while storing legitimate copies in /usr/bin/dpkgd/. The document outlines persistence via init/cron and provides step-by-step remediation: identify and kill processes, remove artefacts, restore binaries, check cron, and optionally use AV (e.g., ClamAV). While the botnet is older, the guidance emphasizes it remains a relevant threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.