Rocke

G0106

Threat group.View on attack.mitre.org

About this group

Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "rocke@live.cn" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1014
Rootkit

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1018
Remote System Discovery

Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them.

T1021.004
SSH

Rocke has spread its coinminer via SSH.

T1027
Obfuscated Files or Information

Rocke has modified UPX headers after packing files to break unpackers.

T1027.002
Software Packing

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1027.004
Compile After Delivery

Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).

T1036.005
Match Legitimate Resource Name or Location

Rocke has used shell scripts which download mining executables and saves them with the filename "java".

T1037
Boot or Logon Initialization Scripts

Rocke has installed an "init.d" startup script to maintain persistence.

T1046
Network Service Discovery

Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers.

T1053.003
Cron

Rocke installed a cron job that downloaded and executed files from the C2.

T1055.002
Portable Executable Injection

Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe.

T1057
Process Discovery

Rocke can detect a running process's PID on the infected machine.

T1059.004
Unix Shell

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.

T1059.006
Python

Rocke has used Python-based malware to install and spread their coinminer.

T1070.004
File Deletion

Rocke has deleted files on infected machines.

View all 36 procedure examples

Software0

None recorded.

Campaigns0

None recorded.

References1

  1. Talos Rocke August 2018 Open source
    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.