The Rocke Group deployed Pro-Ocean, a cloud-focused cryptojacking malware family designed to mine Monero while improving stealth, persistence, and worm-like propagation across compromised environments. Palo Alto Networks Unit 42 reported that the malware targets vulnerable services including Apache ActiveMQ via CVE-2016-3088, Oracle WebLogic via CVE-2017-10271, and unsecured Redis instances, with notable focus on Alibaba Cloud and Tencent Cloud deployments. Written in Go, Pro-Ocean hides an embedded XMRig miner behind multiple obfuscation layers and organizes its activity into four modules: hiding, mining, infecting, and watchdog.
The malware’s hiding module abuses LD_PRELOAD and /etc/ld.so.preload to conceal files and processes, while the infection module scans local subnets and uses public exploits to spread laterally. Its installation routine removes competing malware and miners, disables iptables, attempts SSH-key-based movement between systems, and uninstalls cloud monitoring agents associated with Tencent Cloud and Alibaba Cloud. A watchdog component maintains persistence and kills high-CPU processes so the miner can maximize resource consumption on infected hosts.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Unit 42 had previously documented cloud-targeted malware used by the Rocke Group for Monero cryptojacking. The reference explicitly anchors this earlier reporting to 2019.
Cisco Talos published research on the Rocke group's Monero-mining operations, documenting the threat actor's activity before the later 2019 and subsequent variant reports already in the timeline.
Intezer reported on a Rocke Group Linux/cloud cryptojacking malware variant that spreads laterally using saved SSH keys from known_hosts, brute-forces SSH, Redis, and Jenkins, and exploits Jenkins and ActiveMQ flaws. The report also detailed persistence via cron, bashrc, and a systemd service, plus DNS-over-HTTPS C2 resolution and XMRig miner deployment.
Unit 42 identified Pro-Ocean as a revised version of the Rocke Group’s cloud-targeted cryptojacking malware. The new variant adds stronger rootkit and worm capabilities and targets vulnerable cloud applications and unsecured Redis instances, with emphasis on Alibaba Cloud and Tencent Cloud environments.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourceunit42.paloaltonetworks.com
Open sourcefortinet.com
Open sourceblog.talosintelligence.com
Open sourcejenkins.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.