Rocke
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Rocke Group, also referred to simply as Rocke, is identified in open sources as operating from China. The actor first gained noticeable attention in early May 2020 when it leveraged weaknesses in the SaltStack automation and configuration management framework. The specific target of the intrusion was the Xen Orchestra platform, a web‑based interface used to manage XenServer virtualization environments. By focusing on this management layer, the actor was able to reach multiple virtual machines hosted within the infrastructure. The incident was disclosed by Xen Orchestra in a public blog post that detailed the timeline and impact of the activity.
Initial access was achieved through exploitation of two related vulnerabilities, CVE-2020-11651 and CVE-2020-11652, which allow unauthenticated command execution on SaltStack masters. Once inside, the actor deployed a cryptocurrency mining script that began consuming CPU resources on the compromised virtual machines. The mining process caused noticeable service degradation, including high processor usage and the inadvertent deactivation of local firewall rules on the affected hosts. Forensic analysis indicated that the payload did not contain any persistence mechanisms, such as scheduled tasks or startup entries, and left no alterations to core system files or configuration data. No evidence of data exfiltration was found; the actor did not access GPG signing keys, customer credential stores, or payment information. Remediation involved rebooting the virtual machines, disabling the SaltStack service across the environment, and implementing additional network segmentation through VPNs to prevent further abuse.
Public attribution links the activity to a China‑based threat actor, but the source material does not elaborate on any state sponsorship, criminal consortium, or affiliate network. No other campaigns, malware families, or toolsets are described in the available reporting beyond the SaltStack‑driven cryptojacking incident. Consequently, the known profile of Rocke Group is limited to the observed exploitation of SaltStack vulnerabilities, the deployment of a cryptocurrency miner, and the geographic association with China. All statements above are derived solely from the disclosed incident details and the provided context.
Incidents
Attributed incidents are available to members.
1 incident