Rocke
MITRE ATT&CK: G0106 View on attack.mitre.org
Aliases: Aged Libra, Rocke
- First seen
- 2018-07-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:58:04
Targeted industries: technology-and-telecommunications financial-services
Context
Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "[email protected]" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.
Detection coverage
- 641 Sigma rules
Malware & tools used
- Exploit Public-Facing Application (attack-pattern)
- Rootkit (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Web Service (attack-pattern)
- Unix Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Compute Hijacking (attack-pattern)
- Compile After Delivery (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Cron (attack-pattern)
- Python (attack-pattern)
- Network Service Discovery (attack-pattern)
- Portable Executable Injection (attack-pattern)
- Dead Drop Resolver (attack-pattern)
- Boot or Logon Initialization Scripts (attack-pattern)
- Software Packing (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Linux and Mac Permissions (attack-pattern)
- Process Discovery (attack-pattern)
- Systemd Service (attack-pattern)
- Remote System Discovery (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
Reports & references
- intezer.com — Blog Technical Analysis Cryptocurrency Mining War On The Cloud (report)
- Cisco Talos — Rocke Champion Of Monero Miners (report)
- Palo Alto Unit 42 — Malware Used By Rocke Group Evolves To Evade Detection By Cloud Security Products (report)
- Palo Alto Unit 42 — Agedlibra (report)
- MITRE ATT&CK — G0106 (report)