Rocke is a cryptojacking malware operation and associated malware family focused primarily on Linux systems, with some activity also documented on Windows. It is known for deploying cryptocurrency miners after exploiting exposed public-facing applications, including Apache Struts, Oracle WebLogic, and Adobe ColdFusion, with observed use of vulnerabilities such as CVE-2017-10271 and CVE-2017-3066. Rocke has also been associated with scanning for exposed services including WebLogic, SSH, and Redis to identify additional victims.
Rocke commonly uses shell scripts and Python-based components to download, install, and launch mining payloads, including additional archives retrieved from remote infrastructure and extracted on the victim host. The operation has abused legitimate web services such as Pastebin, Gitee, and GitLab for payload hosting, command-and-control, and dead-drop resolution. Pastebin has been used to check malware versions and redirect infected systems to updated payload locations.
Its tooling emphasizes defense evasion and miner monopolization. Observed behaviors include detecting and uninstalling antivirus software, killing competing miner processes, adding firewall rules to block rival miners, clearing logs, deleting files, and altering timestamps to hinder forensic analysis. Rocke has also used modified UPX packing to frustrate static analysis, including altered packer headers, and has deployed userland rootkit-style hiding by modifying dynamic loader behavior to conceal mining components and related processes.
Persistence mechanisms attributed to Rocke include cron jobs, init.d startup scripts, systemd services on Linux, and packed files placed for persistence on Windows. Lateral movement and propagation have been observed through SSH, including reuse of private keys present on compromised hosts and attempts to connect to systems listed in known_hosts. Additional behaviors include process discovery and downloading further malicious files for staging and execution.
Rocke is best characterized as a Linux-focused cryptomining intrusion set whose malware combines downloader functionality, persistence, defense evasion, and propagation to sustain illicit cryptocurrency mining across compromised environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.
Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.
ClamAV signatures include "Unix.Downloader.Rocke" in the list of malware activity associated with ongoing exploitation campaigns.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
“DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files… actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe … has used legitimate names and locations for files to evade defenses.”
"...used tasklist to enumerate processes..."; "...used the ps command to list processes..."; "...calling CreateToolhelp32Snapshot... to enumerate the running processes..."
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a competing cryptomining malware family whose processes are terminated by lambsys.
A Linux cryptomining family/lineage referenced both as a rival family targeted by lambsys and as the most plausible technique lineage for the campaign, based on shared SSH worming and cleanup behaviors.
Referenced as an example of malware using modified UPX packing to evade static parser detection.
Unix downloader referenced via detection signatures as associated with malware activity seen during Log4j exploitation campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.