Rocke is a cryptojacking threat group focused on compromising Linux and cloud-hosted environments to deploy Monero mining malware. The group has been associated with cloud-targeted campaigns since at least 2019 and is also referred to as Iron Group. Its operations emphasize monetization through illicit cryptocurrency mining rather than espionage or destructive effects. Rocke commonly targets exposed or weakly secured internet-facing services and cloud workloads, including vulnerable enterprise applications and misconfigured infrastructure. Reported intrusion vectors and propagation methods include exploitation of Apache ActiveMQ via CVE-2016-3088, Oracle WebLogic via CVE-2017-10271, Jenkins via CVE-2018-1000861 and CVE-2019-1003000, unsecured Redis instances, and brute-force activity against SSH and Redis. The group has shown particular interest in cloud environments associated with Chinese providers such as Alibaba Cloud and Tencent Cloud. Operationally, Rocke uses staged shell-script infection chains to download and execute additional payloads, often with redundant retrieval paths and public code-hosting or paste services for resilience. The group has also used compile-after-delivery tradecraft, delivering malware as C source files and compiling them locally with GCC. Payloads have included Go-based loaders and managers, Python-based loader stages, and XMRig-derived mining components. Rocke malware has been observed extracting compressed archives, embedding or unpacking miner components, and using modified UPX-style packing markers such as LSD! to hinder static detection. Persistence and stealth are central to Rocke operations. The group establishes persistence through cron jobs, boot-time services, and in some cases startup-folder artifacts on Windows. On Linux, Rocke has deployed LD_PRELOAD-based userland rootkit functionality, including libprocesshider-style capabilities, to conceal files, processes, network activity, and resource consumption. Malware associated with the group can falsify process or CPU-related information returned to monitoring tools. Rocke also performs process discovery and system profiling, including collecting kernel or architecture information with uname -m and identifying running process IDs. Rocke routinely removes competing miners and other malware, deletes artifacts, and attempts to disable or uninstall defensive tooling. Reported behavior includes terminating rival mining processes, uninstalling antivirus or cloud monitoring agents, and disabling host firewall controls in some campaigns. Lateral movement and worm-like propagation have also been documented through subnet scanning, exploitation of adjacent systems, and attempts to reuse SSH keys or trust relationships to spread within cloud environments. The group’s known capabilities include initial access through exploitation and brute force, reconnaissance and scanning of local or internet-reachable targets, persistence, defense evasion through rootkit-style hiding and packing changes, post-exploitation payload staging, and cryptocurrency theft via unauthorized mining.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.
Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.
the threat actors started targeting systems that run Jenkins by attempting to exploit CVE-2018-1000861 and CVE-2019-1003000
the threat actors started targeting systems that run Jenkins by attempting to exploit CVE-2018-1000861 and CVE-2019-1003000
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
7 more CVEs tied to this actor tracked in Mallory.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only in the annotation list for T1190.
Mentioned as an annotated threat actor associated with Unix shell execution / Linux post-exploitation tradecraft in the detection metadata.
Mentioned only in passing in the annotation metadata for this Splunk detection.
Listed as an example threat actor associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.