ATT&CKReferencesUnit 42 Rocke January 2019

Unit 42 Rocke January 2019

Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1053.003
Cron
GroupRocke

Rocke installed a cron job that downloaded and executed files from the C2.

T1190
Exploit Public-Facing Application
GroupRocke

Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.

T1496.001
Compute Hijacking
GroupRocke

Rocke has distributed cryptomining malware.

T1518.001
Security Software Discovery
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1564.001
Hidden Files and Directories
GroupRocke

Rocke downloaded a file "libprocesshider", which could hide files on the target system.

T1685
Disable or Modify Tools
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.