The BillGates botnet was first disclosed on a Russian IT website in February 2014. IBM Managed Security Services observed a sharp increase in security events associated with this botnet over the span of three days. The traffic subsequently subsided and remained steady until early May. Since May 6, however, the team has observed a noteworthy increase in traffic that has remained elevated. The destination IP associated with the majority of the traffic observed in May 2015 is 202.99.96.6868. This IPs country of origin is China.”]
Source: https://securityintelligence.com/got-linux-billgates-botnet-activity-on-the-rise/