Skip to main content

Rocke Group Mining Malware

A new cryptocurrency mining malware, believed to have been created by the Rocke advanced persistent threat group, has been observed targeting vulnerable Linux web servers.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A new cryptocurrency mining malware, believed to have been created by the Rocke advanced persistent threat group, has been observed targeting vulnerable Linux web servers.


Threat details

The Rocke group will scan for vulnerable servers before deploying known exploits to gain access to them. The unnamed malware is then installed and a connection to a command and control server is made

Once a C2 connection is made, the malware will download a shell script with further instructions before creating cronjobs to maintain persistence, terminating other cryptocurrency mining processes on the device and adding iptables rules to prevent them functioning. It will then download and execute a variant of the XMRig mining module, using the libprocessholder tool to disguise the mining process.

Update  

A new Rocke-attributed campaign has been observed using a modified version of their mining malware, written in Go, to target a wider range of servers. In addition to having the full functionality of previous versions, this new variant will attempt to propagate laterally using SSH.

Update  

Rocke recently updated the malware to exploit two Jenkins vulnerabilities, CVE-2018-1000861 and CVE-2019-1003000.


Threat updates

Date Update
5 Feb 2021 Rocke Group Develops Worm Capabilities

The Pro-Ocean cryptojacking malware developed by Rocke Group can now self-propagate by exploiting unpatched servers. This infection module first determines the host's public IP and then attempts to attack all hosts in the same 16-bit subnet. Pro-Ocean attempts to exploit Apache ActiveMQ CVE-2016-3088, Oracle WebLogic CVE-2017-10271 and insecure Redis instances. Pro-Ocean also now includes rootkit capabilities to help evade detection.


Remediation steps

Type Step

To prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.


Indicators of compromise

Network indicators

Domains

  • shop.168bee[.]com
  • pool.minexmr[.]com
Host indicators

File hashes (SHA-256):

  • 4ff33180d326765d92e32ec5580f54495bfcdd58a85f908a7ece8d0aedbe5597
  • 220c2ebacafde95ebf4af12bf0d8eedb6004edd103ecb1d6363e7eb5a3e62c01
  • a81424ec81849950616f932c79db593147b8a01cc6d06d279fd05d61103abdb7
  • 070afdbb4c2c9e499d55cb8fbc08f98e95725b98682586d42f84fd7181eae1cb
  • 0a3898da2c6e31f1eed4497c4e4e3cf24138981f35cb3d190b81ba4b24ab3df0
  • 26a126fd5cd47b62bb5ae3116a509caf84da1ccd414e632f898aec0948cb0dbf
  • 37e1c05cc683bac5fe97763023a228a4ca4e0439acc94695724f67b7e0275ece
  • d3e95ae2f01be948dd11157873b3c84cb3e76dea1b382bcfb2c0cb09a949497c
  • 713b5447a51a4b930222491a2dfb5b948a5da6860d80cd8663c99432c1e0812f
  • 0f7abdceae4353c4a6a8ed6b5d261df0f94c2c52709dd50d38003192492e7d3b
  • bfea86bb68b51c6875d541c92bb48b38298982efbe12cf918873642235b99eeb
  • 575945f6f5149dc48c4a665fcab0cbdbedec1e18b887abe837ed987a7253ad02
  • abb36bc19b82a026f7d70919c64ed987ebb71420b04bb848275547e99da485bd
  • 7888925fe143add65f2ad928a7ee4e4b864d421fde57fac0cb2b218e70fe4d31

File names:

  • pro__autolk.sh
  • pro__automig.sh
  • pro__autorkt.sh
  • pro__autoscan.sh
  • pro__cfg
  • pro__wlib.c
  • proc__bioset.sh
  • proc__o0mig
  • proc__scanr.py
  • pro__o0cean
  • pro__o0cean
  • proc__sysagent.service
  • .program__daemonload
  • .program__kill30

 


Last edited: 5 February 2021 8:39 am