G0106 · 36 ATT&CK techniques · 0 correlated reports

Rocke

Aliases: None listed

Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "rocke@live.cn" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.

Open interactive actor investigation

ATT&CK techniques

Correlated CTI and IR reports

Continue the investigation