Rocke, Iron Group

Description

(Talos) This threat actor initially came to our attention in April 2018, leveraging both Western and Chinese Git repositories to deliver malware to honeypot systems vulnerable to an Apache Struts vulnerability.

In late July, we became aware that the same actor was engaged in another similar campaign. Through our investigation into this new campaign, we were able to uncover more details about the actor.

Names

NameName-Giver
RockeTalos
Iron GroupIntezer
Aged LibraPalo Alto

Country

Motivation

  • Financial gain

First Seen

2018

Tools

Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

bacc587d-719b-4555-bc37-db7a9455dc6a

Last Card Change

2024-03-10