NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Rocke

Rocke

G0106 China MITRE ATT&CK →

Overview

Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "[email protected]" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 36 techniques across 10 tactics

Reporting (1)