Rocke Group Mining Malware
A new cryptocurrency mining malware, believed to have been created by the Rocke advanced persistent threat group, has been observed targeting vulnerable Linux web servers.
Summary
A new cryptocurrency mining malware, believed to have been created by the Rocke advanced persistent threat group, has been observed targeting vulnerable Linux web servers.
Affected platforms
The following platforms are known to be affected:
Threat details
The Rocke group will scan for vulnerable servers before deploying known exploits to gain access to them. The unnamed malware is then installed and a connection to a command and control server is made
Once a C2 connection is made, the malware will download a shell script with further instructions before creating cronjobs to maintain persistence, terminating other cryptocurrency mining processes on the device and adding iptables rules to prevent them functioning. It will then download and execute a variant of the XMRig mining module, using the libprocessholder tool to disguise the mining process.
Update
A new Rocke-attributed campaign has been observed using a modified version of their mining malware, written in Go, to target a wider range of servers. In addition to having the full functionality of previous versions, this new variant will attempt to propagate laterally using SSH.
Update
Rocke recently updated the malware to exploit two Jenkins vulnerabilities, CVE-2018-1000861 and CVE-2019-1003000.
Threat updates
| Date | Update |
|---|---|
| 5 Feb 2021 |
Rocke Group Develops Worm Capabilities
The Pro-Ocean cryptojacking malware developed by Rocke Group can now self-propagate by exploiting unpatched servers. This infection module first determines the host's public IP and then attempts to attack all hosts in the same 16-bit subnet. Pro-Ocean attempts to exploit Apache ActiveMQ CVE-2016-3088, Oracle WebLogic CVE-2017-10271 and insecure Redis instances. Pro-Ocean also now includes rootkit capabilities to help evade detection. |
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Indicators of compromise
CVE Vulnerabilities
Last edited: 5 February 2021 8:39 am