NEW: Group Profiler — instant APT intel lookup. Try it →

Rocke

G0106 China MITRE ATT&CK →

Overview

Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "[email protected]" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.

Naming & attribution

Rocke is tracked under 1 names across the industry. It uses 36 documented ATT&CK techniques — more than 72% of the 174 groups tracked here.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1055.002 Portable Executable Injection — used by 2 of 174 groups
  • T1053.003 Cron — used by 3 of 174 groups
  • T1222.002 Linux and Mac Permissions — used by 3 of 174 groups
  • T1543.002 Systemd Service — used by 3 of 174 groups
  • T1574.006 Dynamic Linker Hijacking — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TeamTNT — 23 shared techniques (33% overlap)
  • APT41 China — 18 shared techniques (18% overlap)
  • BlackByte — 12 shared techniques (17% overlap)
  • Tropic Trooper China — 11 shared techniques (17% overlap)
  • APT39 Iran — 12 shared techniques (16% overlap)
  • Gamaredon Group Russia — 14 shared techniques (15% overlap)

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 36 techniques across 10 tactics

Reporting (1)