LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0106: Rocke

Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "rocke@live.cn" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.[1]

EnterpriseG0106GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Rocke matters because the ATT&CK entry describes a group whose apparent objective was cryptojacking: stealing victim compute resources to mine cryptocurrency. For leaders, the business issue is not only malware cleanup; it is unexpected cloud or infrastructure cost, degraded service performance, and evidence that internet-facing systems, SSH access, persistence controls, and egress monitoring may be weak.

Executive priority

Treat this as a resilience and exposure-management use case. Ask whether public-facing applications are patched and inventoried, whether SSH and privileged access are governed, whether SOC telemetry can see Unix shell/Python execution and scheduled persistence, and whether finance/operations would notice abnormal compute consumption. Because MITRE provides no official detection text and the group platform field is not specified, priority should be based on local exposure to the related techniques rather than assumptions about where Rocke is present.

Technical view

The relationship context points defenders toward a chain involving exploitation of public-facing applications, discovery of systems/services/processes, SSH-based lateral movement, Unix shell and Python execution, tool transfer, web-based C2, obfuscation/deobfuscation, persistence through cron or boot/logon scripts, file deletion/timestomping, and possible rootkit or injection-style stealth. Validate coverage around these behaviors, especially on internet-facing Unix-like, cloud, ESXi, container, and network-device contexts where related techniques list support them, while noting that the Rocke group object itself does not specify platforms or tactics.

Likely telemetry

  • Internet-facing application, web server, container, IaaS, and ESXi exposure logs relevant to exploitation attempts and successful access
  • SSH authentication, session, source/destination, and account-use records
  • Process execution and command-line telemetry for Unix shells, Python, compilers, scanners, download utilities, and miner-like processes where locally applicable
  • Cron, boot/logon initialization script, service, and startup file change records
  • Network flow, DNS, proxy, and HTTP/S telemetry for external web services, tool transfer, and command-and-control-like connections

Detection direction

  • Because MITRE supplies no official detection guidance for Rocke, build detections from the related ATT&CK techniques rather than a single group signature.
  • Correlate public-facing application anomalies with follow-on shell/Python execution, file downloads, service discovery, process discovery, and new scheduled tasks.
  • Tune SSH detections for unusual source hosts, first-seen account-to-host pairs, unexpected lateral movement, and activity following exploitation indicators; account for legitimate administration to reduce false positives.
  • Baseline cron and boot/logon initialization scripts so new or modified persistence entries stand out, especially when paired with outbound web traffic or high CPU use.
  • Look for obfuscated or packed artifacts, decode/deobfuscation activity, suspicious file deletion, and timestamp inconsistencies, but avoid over-reliance on file signatures because several related techniques explicitly support stealth.

Mitigation priorities

  • Start with exposure reduction: maintain an accurate inventory of internet-facing applications and services, prioritize patching or configuration fixes for externally reachable weaknesses, and remove unnecessary exposure.
  • Harden identity and remote access: restrict SSH access, enforce least privilege, review valid account use, and monitor administrative access paths.
  • Limit execution and persistence opportunities by controlling script execution where feasible, reviewing cron and initialization paths, and applying change control to startup mechanisms.
  • Constrain and inspect egress paths for servers and cloud workloads, especially outbound web traffic and file transfer patterns not required for business operations.
  • Improve host and workload visibility for process execution, file integrity, scheduled tasks, and resource consumption so cryptojacking-style activity is observable before it becomes an availability or cost issue.
Additional notes and limits

The ATT&CK description characterizes Rocke as an alleged Chinese-speaking adversary with an apparent cryptojacking objective and notes unconfirmed overlap with Iron Cybercrime Group. The relationship set is broad and provides the practical defensive map: initial access, discovery, lateral movement, execution, persistence, stealth, tool transfer, and web-based command-and-control behaviors. Use this object primarily to test whether controls can detect and respond to resource-theft intrusions rather than to make attribution claims.

The supplied group object has no official detection text, no specified platforms, and no specified tactics. Platform and tactic references in this take come only from related technique context, not from the Rocke group field itself. Local telemetry, asset exposure, application stack, cloud usage, and account behavior are required to determine actual risk and detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Rocke

Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "rocke@live.cn" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

36 rows
DomainIDNameRelationship / procedure
EnterpriseT1190Exploit Public-Facing Application

Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.[1][2]

EnterpriseT1014Rootkit

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.[3]

EnterpriseT1027Obfuscated Files or Information

Rocke has modified UPX headers after packing files to break unpackers.[3]

EnterpriseT1102Web Service

Rocke has used Pastebin, Gitee, and GitLab for Command and Control.[3][1]

EnterpriseT1059.004Unix ShellSub-technique

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.[1]

EnterpriseT1082System Information Discovery

Rocke has used uname -m to collect the name and information about the infected system's kernel.[3]

EnterpriseT1071Application Layer Protocol

Rocke issued wget requests from infected systems to the C2.[1]

EnterpriseT1105Ingress Tool Transfer

Rocke used malware to download additional malicious files to the target system.[1]

EnterpriseT1496.001Compute HijackingSub-technique

Rocke has distributed cryptomining malware.[1][2]

EnterpriseT1027.004Compile After DeliverySub-technique

Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).[3]

EnterpriseT1574.006Dynamic Linker HijackingSub-technique

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.[3]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

Rocke downloaded a file "libprocesshider", which could hide files on the target system.[1][2]

EnterpriseT1053.003CronSub-technique

Rocke installed a cron job that downloaded and executed files from the C2.[1][2][3]

EnterpriseT1059.006PythonSub-technique

Rocke has used Python-based malware to install and spread their coinminer.[3]

EnterpriseT1046Network Service Discovery

Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers.[1][3]

EnterpriseT1055.002Portable Executable InjectionSub-technique

Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe.[1]

EnterpriseT1102.001Dead Drop ResolverSub-technique

Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware.[3]

EnterpriseT1037Boot or Logon Initialization Scripts

Rocke has installed an "init.d" startup script to maintain persistence.[3]

EnterpriseT1027.002Software PackingSub-technique

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.[1][2][3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.[1]

EnterpriseT1222.002Linux and Mac PermissionsSub-technique

Rocke has changed file permissions of files so they could not be modified.[3]

EnterpriseT1057Process Discovery

Rocke can detect a running process's PID on the infected machine.[3]

EnterpriseT1543.002Systemd ServiceSub-technique

Rocke has installed a systemd service script to maintain persistence.[3]

EnterpriseT1018Remote System Discovery

Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them.[1]

EnterpriseT1686Disable or Modify System Firewall

Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Rocke has extracted tar.gz files after downloading them from a C2 server.[1]

EnterpriseT1685.006Clear Linux or Mac System LogsSub-technique

Rocke has cleared log files within the /var/log/ folder.[3]

EnterpriseT1552.004Private KeysSub-technique

Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network.[3]

EnterpriseT1070.004File DeletionSub-technique

Rocke has deleted files on infected machines.[3]

EnterpriseT1071.001Web ProtocolsSub-technique

Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol.[3]

EnterpriseT1685Disable or Modify Tools

Rocke used scripts which detected and uninstalled antivirus software.[1][2]

EnterpriseT1571Non-Standard Port

Rocke's miner connects to a C2 server using port 51640.[3]

EnterpriseT1021.004SSHSub-technique

Rocke has spread its coinminer via SSH.[3]

EnterpriseT1070.006TimestompSub-technique

Rocke has changed the time stamp of certain files.[3]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Rocke has used shell scripts which download mining executables and saves them with the filename "java".[1]

EnterpriseT1518.001Security Software DiscoverySub-technique

Rocke used scripts which detected and uninstalled antivirus software.[1][2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
493d858defd7452e...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle493d858defd7…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  2. [2]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  3. [3]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  4. [4]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  5. [5]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  6. [6]
    mitre-attackG0106
    Open source URL
  7. [7]
    mitre-attackG0106
    Open source URL
  8. [8]
    mitre-attackG0106
    Open source URL
  9. [9]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  10. [10]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  11. [11]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  12. [12]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  13. [13]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  14. [14]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  15. [15]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  16. [16]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  17. [17]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  18. [18]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  19. [19]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  20. [20]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  21. [21]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  22. [22]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  23. [23]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  24. [24]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  25. [25]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  26. [26]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  27. [27]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  28. [28]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  29. [29]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  30. [30]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  31. [31]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  32. [32]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  33. [33]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  34. [34]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  35. [35]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  36. [36]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  37. [37]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  38. [38]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  39. [39]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  40. [40]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  41. [41]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  42. [42]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  43. [43]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  44. [44]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  45. [45]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  46. [46]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  47. [47]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  48. [48]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  49. [49]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  50. [50]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  51. [51]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  52. [52]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  53. [53]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  54. [54]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  55. [55]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  56. [56]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  57. [57]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  58. [58]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  59. [59]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  60. [60]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  61. [61]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  62. [62]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  63. [63]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  64. [64]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  65. [65]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  66. [66]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  67. [67]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  68. [68]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  69. [69]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  70. [70]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  71. [71]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  72. [72]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  73. [73]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  74. [74]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  75. [75]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  76. [76]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  77. [77]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  78. [78]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  79. [79]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  80. [80]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  81. [81]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  82. [82]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  83. [83]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
  84. [84]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  85. [85]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  86. [86]
    Anomali Rocke March 2019

    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

    Open source URL
  87. [87]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  88. [88]
    Talos Rocke August 2018

    Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

    Open source URL
  89. [89]
    Unit 42 Rocke January 2019

    Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.