not MITRE’s ATT&CK Group
Rocke
How MITRE ATT&CK characterizes this group1: Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "[email protected]" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.
Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.
Read as a financially-motivated operator.
A crimeware classification means the objective is money — access brokering, theft, fraud, or commodity malware. Volume and opportunism over stealth; the path tends to monetize fast. All tradecraft below is sourced to MITRE ATT&CK.
Known for
— signature moves, each sourced to ATT&CKTradecraft heatmap
— ATT&CK techniques mapped onto the five attacker-outcome narrativesEach row is a documented technique (MITRE ATT&CK). Each column is one of the five attacker-outcome narratives a defender funds against. A filled cell means this technique’s own ATT&CK tactic defensibly advances that outcome. The mapping of technique→outcome is our editorial alignment over ATT&CK's tactic data, not a separately-sourced MITRE edge. A filled cell means one of the technique's own ATT&CK tactics defensibly advances that outcome; enabler tactics (C2, Defense Evasion, Discovery) heat no column.
Reach: this actor’s cited techniques light columns 1·2·3·5 — furthest is 5 · Lights out. (furthest-position idiom, reused from the landing map).
Arsenal
— named tools & malware ATT&CK attributes to this groupATT&CK attributes no software to G0106 at this snapshot. Absence is a finding, not a claim of harmlessness.
Campaign highlights
— attributed operations in the ATT&CK recordNo attributed campaigns — coverage gap
Latest activity
— with explicit confidence, and what we cannot yet claimsnapshot
The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.