Threat group.View on attack.mitre.org
Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "rocke@live.cn" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1018 Remote System Discovery |
Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them. |
| T1021.004 SSH |
Rocke has spread its coinminer via SSH. |
| T1027 Obfuscated Files or Information |
Rocke has modified UPX headers after packing files to break unpackers. |
| T1027.002 Software Packing |
Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1027.004 Compile After Delivery |
Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC). |
| T1036.005 Match Legitimate Resource Name or Location |
Rocke has used shell scripts which download mining executables and saves them with the filename "java". |
| T1037 Boot or Logon Initialization Scripts |
Rocke has installed an "init.d" startup script to maintain persistence. |
| T1046 Network Service Discovery |
Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers. |
| T1053.003 Cron |
Rocke installed a cron job that downloaded and executed files from the C2. |
| T1055.002 Portable Executable Injection |
Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe. |
| T1057 Process Discovery |
Rocke can detect a running process's PID on the infected machine. |
| T1059.004 Unix Shell |
Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware. |
| T1059.006 Python |
Rocke has used Python-based malware to install and spread their coinminer. |
| T1070.004 File Deletion |
Rocke has deleted files on infected machines. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.