Rocke (Aged Libra) has exploited public-facing app vulnerabilities since 2018, executing commands via Unix Shell and Cron.
Analyst brief
Actor "Rocke" (also known as Aged Libra) is a threat group active since 2018, primarily exploiting vulnerabilities in public-facing applications like Apache Struts for initial access, followed by executing commands via Unix Shell and Cron jobs. Key TTPs include using Boot scripts for persistence, Rootkits for stealth, SSH for lateral movement, and accessing private keys for credential theft, alongside Windows AutoStart registry entries for persistence. Defenders should focus on rigorous patch management for public-facing applications, monitor for unusual Cron jobs or Unix Shell executions, implement network segmentation to limit lateral movement via stolen SSH keys, and be alert to any modifications to Linux system firewall settings.
Rocke
Aged Libra
unknown
This threat actor initially came to our attention in April 2018, leveraging both Western and Chinese Git repositories to deliver malware to honeypot systems vulnerable to an Apache Struts vulnerability.
In late July, we became aware that the same actor was engaged in another similar campaign. Through our investigation into this new campaign, we were able to uncover more details about the actor.