Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In our analysis, we found Pro-Ocean targeting... Oracle WebLogic (CVE-2017-10271)... The list of vulnerable software that Pro-Ocean exploits includes: Oracle WebLogic – CVE-2017-10271. | We’ve named the malware Pro-Ocean after the name the attacker chose for the installation script. Pro-Ocean uses known vulnerabilities to target cloud applications.
In our analysis, we found Pro-Ocean targeting Apache ActiveMQ (CVE-2016-3088)... The list of vulnerable software that Pro-Ocean exploits includes: Apache ActiveMQ – CVE-2016-3088. | We’ve named the malware Pro-Ocean after the name the attacker chose for the installation script. Pro-Ocean uses known vulnerabilities to target cloud applications.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We’ve named the malware Pro-Ocean after the name the attacker chose for the installation script. Pro-Ocean uses known vulnerabilities to target cloud applications.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Here, we uncover a revised version of the same cloud-targeted cryptojacking malware, which now includes new and improved rootkit and worm capabilities.
The miner seeks to hide using several obfuscation layers on top of the malicious code... The modules are gzipped inside the unpacked binary.
The binary is packed using UPX... However, in this case, the UPX magic string has been deleted from the binary, and therefore, static analysis tools cannot identify this binary as UPX and unpack it.
Although Pro-Ocean attempts to disguise itself as benign, it packs an XMRig miner...
Disable the iptables firewall so that the malware will have full access to the internet.
This script retrieves the machine’s public IP by accessing an online service that does so in the address "ident.me" and then tries to infect all the machines in the same 16-bit subnet (e.g. 10.0.X.X). It does this by blindly executing public exploits one after the other in the hope of finding unpatched software it can exploit.
Once it finds unpatched software and exploits it, the Python script sends a payload that will download an installation script from a malicious HTTP server... After laying the groundwork, the installation script will determine the machine CPU architecture and try to download the corresponding binary using various tools including curl, wget, python2, python3 and PHP.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior example of Monero-focused cryptojacking activity.
Cloud-targeted cryptojacking malware used by the Rocke Group to mine Monero. It includes four modules for hiding/rootkit behavior, mining, worm-like infection, and watchdog persistence. It targets Apache ActiveMQ, Oracle WebLogic, and insecure Redis instances, attempts lateral spread across local subnets, removes competing miners, disables defenses, and uses LD_PRELOAD-based process/file hiding plus persistence mechanisms such as services and cron jobs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.