Rocke is a Linux-focused opportunistic cryptojacking threat actor associated with cloud and server intrusions, especially the deployment of cryptocurrency miners on exposed or weakly secured systems. The group is widely linked to the KORKERDS cryptomining ecosystem and has been observed targeting Linux servers through exploitation of public-facing applications and post-compromise shell-based tooling. Rocke is known for using Unix shell scripts extensively for payload delivery, execution, and system modification, and for evolving from simple script-based miners to Golang-based payloads with more durable persistence mechanisms. Rocke commonly establishes persistence through cron-based scheduled execution and system startup mechanisms, including boot-time autostart via systemd services. Reported tradecraft includes placing or modifying scheduled tasks in common cron locations and ensuring miner payloads relaunch after reboot. The actor has also been associated with privileged container abuse in Linux environments and with post-exploitation behaviors on compromised hosts. Operationally, Rocke performs host discovery and environment profiling, including collecting kernel and architecture information. The group has been observed downloading additional tooling, extracting compressed archives, retrieving payloads over HTTP or HTTPS with standard command-line utilities, and using stealth measures such as masquerading and packed binaries. Rocke has also used rootkit-like userland hiding components and scripts that detect and uninstall antivirus software, reflecting a strong emphasis on defense evasion and maintaining exclusive access to compromised resources. Rocke’s activity is primarily financially motivated, with the objective of illicit cryptocurrency mining rather than espionage or destructive effects. The actor is notable for Linux persistence, miner deployment, security-tool removal, and opportunistic exploitation at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.
Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
5 more CVEs tied to this actor tracked in Mallory.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only in the annotation list for T1190.
Mentioned as an annotated threat actor associated with Unix shell execution / Linux post-exploitation tradecraft in the detection metadata.
Mentioned only in passing in the annotation metadata for this Splunk detection.
Listed as an example threat actor associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.