Rocke
Also reported as Aged Libra and Iron Group. Linked to China by one source.
Reports per quarter
Techniques seen in the last two years
- T1021 3 reports reports only
- T1036 3 reports reports only
- T1190 3 reports in ATT&CK
- T1018 2 reports in ATT&CK
- T1046 2 reports in ATT&CK
- T1057 2 reports in ATT&CK
- T1071 2 reports in ATT&CK
- T1078 2 reports reports only
- T1110 2 reports reports only
- T1132 2 reports reports only
Show all 14 techniques Show fewer
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2016-3088 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-10271 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-3066 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2018-1000861 KEV
- CVE-2018-11776 KEV
- CVE-2019-0708 KEV ransomware
- CVE-2019-1003000
- CVE-2019-1003001
- CVE-2019-16759 KEV
Show all 35 CVEs Show fewer
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2020-17530 KEV
- CVE-2020-2551 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2022-0543 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-34305
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Rocke, Iron Group - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Rocke, Iron Group - Threat Group Cards: A Threat Actor Encyclopedia
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
Show all 35 reports Show fewer
-
CoinStomp Malware Family Targets Asian Cloud Service Providers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CoinStomp Malware Family Targets Asian Cloud Service Providers
-
TeamTNT Using WatchDog TTPs to Expand Its Cryptojacking Footprint
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Using WatchDog TTPs to Expand Its Cryptojacking Footprint
-
Rocke Group Actively Targeting the Cloud- Wants Your SSH Keys
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rocke Group Actively Targeting the Cloud- Wants Your SSH Keys
-
New cryptojacking malware called Pro-Ocean is now attacking Apache, Oracle and Redis servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New cryptojacking malware called Pro-Ocean is now attacking Apache, Oracle and Redis servers
-
Pro-Ocean- Rocke Group’s New Cryptojacking Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pro-Ocean- Rocke Group’s New Cryptojacking Malware
-
Threat Research- New Rocke Variant Ready to Box Any Mining Challengers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Research- New Rocke Variant Ready to Box Any Mining Challengers
-
One year later- The VPNFilter catastrophe that wasn't
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor One year later- The VPNFilter catastrophe that wasn't
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Technical Analysis- Pacha Group Competing against Rocke Group for Cryptocurrency Mining Foothold on the Cloud
-
CVE-2019-3396: Exploiting the Confluence Vulnerability
The original link failed its last check. Original publisher Detailsfor CVE-2019-3396: Exploiting the Confluence Vulnerability
-
Rocke Evolves Its Arsenal With a New Malware Family Written in Golang
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rocke Evolves Its Arsenal With a New Malware Family Written in Golang
-
Malware Used by “Rocke” Group Evolves to Evade Detection by Cloud Security Products
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Used by “Rocke” Group Evolves to Evade Detection by Cloud Security Products
-
Malware Used by “Rocke” Group Evolves to Evade Detection by Cloud Security Products
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Used by “Rocke” Group Evolves to Evade Detection by Cloud Security Products
-
Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
-
Rocke- The Champion of Monero Miners
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rocke- The Champion of Monero Miners
Newest first. Details opens the report in Explore.