Rocke

MITRE ATT&CK: G0106 View on attack.mitre.org

Aliases: Aged Libra, Rocke

First seen
2018-07-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:58:04

Targeted industries: technology-and-telecommunications financial-services

Context

Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "[email protected]" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.

Detection coverage

  • 641 Sigma rules

Malware & tools used

  • Exploit Public-Facing Application (attack-pattern)
  • Rootkit (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Web Service (attack-pattern)
  • Unix Shell (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Compute Hijacking (attack-pattern)
  • Compile After Delivery (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Cron (attack-pattern)
  • Python (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Portable Executable Injection (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Boot or Logon Initialization Scripts (attack-pattern)
  • Software Packing (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • Process Discovery (attack-pattern)
  • Systemd Service (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)

Reports & references

  • intezer.com — Blog Technical Analysis Cryptocurrency Mining War On The Cloud (report)
  • Cisco Talos — Rocke Champion Of Monero Miners (report)
  • Palo Alto Unit 42 — Malware Used By Rocke Group Evolves To Evade Detection By Cloud Security Products (report)
  • Palo Alto Unit 42 — Agedlibra (report)
  • MITRE ATT&CK — G0106 (report)

External references