Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.2
group
Rocke G0106
- Created
- 26 May 2020
- Last modified
- 31 July 2026
- Alias
- Rocke
Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "rocke@live.cn" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0106
Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them.3
Rocke has modified UPX headers after packing files to break unpackers.5
Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.678
Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).9
Standing G0106
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
73rd percentile · 73% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
66th percentile · 66% of 176 ATT&CK groups have this many tactics spanned or fewer.
9th percentile · 91% of 176 ATT&CK groups have more tools and malware.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
40th percentile · 60% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0106
1266 distinct rules cover the 36 techniques recorded for this group. The 1333 technique-to-rule mappings resolve to 1266 distinct rules, because one rule can cover several techniques. 829 Sigma · 437 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org