Intrusion setG0106
Rocke
Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "rocke@live.cn" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.
- Documented techniques
- 36
- Assessed motivation
- Financial gain
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
initial access1
persistence3
credential access1
discovery5
lateral movement1
command and control6
impact1
defense impairment4
stealth11
- T1014 Rootkit
- T1027 Obfuscated Files or Information
- T1027.002 Software Packing
- T1027.004 Compile After Delivery
- T1036.005 Match Legitimate Resource Name or Location
- T1055.002 Portable Executable Injection
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1140 Deobfuscate/Decode Files or Information
- T1564.001 Hidden Files and Directories
- T1574.006 Dynamic Linker Hijacking