Malware used by “Rocke” group evolves to evade detection by cloud security products

During the analysis, the researchers realized that these samples used by Rocke group adopted new code to uninstall five different cloud security protection and monitoring products from compromised Linux servers. Palo Alto Networks Unit 42 recently captured and investigated new samples of the Linux coin mining malware used by the Rocke group. The family was suspected to be developed by the Iron cybercrime group and it’s also associated with the Xbash malware reported on last month.