[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/rockein-the-netflow/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/rockein-the-netflow/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/ "Cybercrime")  
  [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)

# Rocke'in the NetFlow

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Nathaniel Quist](https://unit42.paloaltonetworks.com/author/nathaniel-quist/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 1, 2019

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cloud Cybersecurity Research](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/)
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Cloud Malware Agent](https://unit42.paloaltonetworks.com/tag/cloud-malware-agent/)
  * [NetFlow](https://unit42.paloaltonetworks.com/tag/netflow/)
  * [Rocke](https://unit42.paloaltonetworks.com/tag/rocke/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/rockein-the-netflow/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/rockein-the-netflow/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Rocke'in%20the%20NetFlow&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Frockein-the-netflow%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Frockein-the-netflow%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frockein-the-netflow%2F&title=Rocke'in%20the%20NetFlow "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frockein-the-netflow%2F&text=Rocke'in%20the%20NetFlow "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Frockein-the-netflow%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Rocke'in%20the%20NetFlow%20https%3A%2F%2Funit42.paloaltonetworks.com%2Frockein-the-netflow%2F "Share in Mastodon")

### Executive Summary

Unit 42 spent six months researching the China-based cybercrime group Rocke, which is the best-known threat actor engaged in cryptomining operations targeting the cloud. We released high-level results from our investigation of Rocke in [our recent cloud threat report](https://unit42.paloaltonetworks.com/cloudy-with-a-chance-of-entropy/). This research report provides a deep dive into our investigation of Rocke, which concluded that the group is able to conduct operations with little interference and limited detection risk.

By analyzing NetFlow data from December 2018 to June 16, 2019, we found that 28.1% of the cloud environments we surveyed had at least one fully established network connection with at least one known Rocke command-and-control (C2) domain. Several of those organizations maintained near daily connections. Meanwhile, 20% of the organizations maintained hourly heartbeats consistent with Rocke tactics, techniques, and procedures (TTPs).

The group has also released a new tool called [Godlua](https://blog.netlab.360.com/an-analysis-of-godlua-backdoor-en/), which could function as an agent, allowing the group's actors to perform additional scripted operations, including denial of service (DoS) attacks, network proxying, and two shell capabilities. Unit 42 also discovered network traffic identification patterns within NetFlow traffic that provide unique insight into Rocke TTPs and how defenders can develop detection capabilities.

#### Intro to Rocke

The activities of Rocke, aka the Iron Group, SystemTen, Kerberods/Khugepageds, and even ex-Rocke, were [originally reported](https://blog.talosintelligence.com/2018/08/rocke-champion-of-monero-miners.html) in August 2018. Researchers have since blogged on its use [of the Golang programming language](https://www.anomali.com/blog/rocke-evolves-its-arsenal-with-a-new-malware-family-written-in-golang) and the new backdoor, [Godlua](https://blog.netlab.360.com/an-analysis-of-godlua-backdoor-en/). There is an operational blog mapping [Rocke operations to the MITRE ATT\&CK framework](https://redcanary.com/blog/rocke-cryptominer/). Unit 42 has also published blogs on the group's [Xbash](https://unit42.paloaltonetworks.com/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/) ransomware tool and its [cloud security evasion and cryptomining techniques](https://unit42.paloaltonetworks.com/malware-used-by-rocke-group-evolves-to-evade-detection-by-cloud-security-products/).

Rocke was initially associated with ransomware campaigns through the use of its Linux-focused Xbash tool, a data-destruction malware similar in functionality to [NotPetya](https://www.wired.com/story/petya-ransomware-ukraine/). NotPetya used the EternalBlue exploit to propagate across a network. Xbash performed lateral movement by leveraging an organization's unpatched vulnerabilities and use of weak passwords, which potentially limited its overall effectiveness. When Rocke compromised an organization, it demanded that victims pay 0.2, 0.15, or 0.02 bitcoin (BTC) to restore lost data. However, Rocke was unable to restore any data since Xbash deleted database tables prior to demanding the ransom. At the time of Unit 42's reporting, Rocke's BTC wallet contained 0.964 BTC (equivalent to US$10,130 today) from just 48 unique transfers.

#### Rocke's Cryptomining Operation

Like Rocke's Xbash malware, the group's first cryptomining operations were written in Python and used Pastebin or GitHub as the code repository from which the first-stage payload was downloaded. As of March 12, 2019, Rocke actors began to also use [Golang](https://www.anomali.com/blog/rocke-evolves-its-arsenal-with-a-new-malware-family-written-in-golang). The first-stage payload directed the victim system to connect to a hardcoded Rocke domain or IP address, which would trigger the download of the second-stage payload.

Unit 42 has observed a distinctive 12-step operation style, which appears to have remained consistent since Rocke was first reported:

* Actor uploads first payload to a third-party site (e.g., Pastebin, GitHub)
* Entices victim to navigate to Pastebin/GitHub (e.g., spear phishing)
* Exploits known vulnerability (e.g., Oracle WebLogic, Adobe ColdFusion, Apache Struts)
* Victim downloads backdoor (e.g., Shell Scripts, JavaScript Backdoor)
* Victim runs the first payload via Python or Golang script and connects to C2 server
* Downloads and executes second payload script, gaining administrative access to the system
* Establishes persistence via cron job commands
* Searchers for and kills previously installed cryptomining processes
* Adds "IPtables" rules to block future cryptomining processes
* Uninstalls agent-based cloud security tools (e.g., Tencent Cloud, Alibaba Cloud)
* Downloads and installs Monero mining software
* Rootkits XMRig mining processes from Linux "ps" using "libprocesshider"

#### Rocke Infrastructure

As of the time of this writing, eight domains have been tied to Rocke C2 operations through hardcoded IP addresses, URL addresses, or domain registration connections (e.g., WHOIS registrant email address). The following chart lays out how the domains fit into the Rocke group infrastructure (see Table 1).

|------------------------|-----------------------|-------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Domain**             | **Rocke Connection**  | **Connection Value**                                                                                                                | **Resolved IP(s)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| sowcar\[.\]com         | Hardcode IOC          | 4592248@gmail\[.\]com                                                                                                               | 23.234.4\[.\]151  23.234.4\[.\]153 27.221.28\[.\]231 27.221.54\[.\]252 36.103.236\[.\]221 36.103.247\[.\]121 36.248.26\[.\]205 42.202.141\[.\]230 42.236.125\[.\]84 42.56.76\[.\]104 43.242.166\[.\]88 59.83.204\[.\]14 60.167.222\[.\]122 61.140.13\[.\]251 104.31.68\[.\]79 104.31.69\[.\]79 113.142.51\[.\]219 113.200.16\[.\]234 116.211.184\[.\]212 118.213.118\[.\]94 118.25.145\[.\]24 122.246.6\[.\]183 125.74.45\[.\]101 150.138.184\[.\]119 182.118.11\[.\]126 182.118.11\[.\]193 182.247.250\[.\]251 182.247.254\[.\]83 183.224.33\[.\]79 211.91.160\[.\]159 211.91.160\[.\]238 218.75.176\[.\]126 219.147.231\[.\]79 221.204.60\[.\]69 |
| thyrsi\[.\]com         | WHOIS Registration    | 4592248@gmail\[.\]com                                                                                                               | 23.234.4\[.\]151  23.234.4\[.\]153 103.52.216\[.\]35 104.27.138\[.\]223 104.27.139\[.\]223 205.185.122\[.\]229 209.141.41\[.\]204                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| w2wz\[.\]cn            | WHOIS Registration    | 4592248@gmail\[.\]com                                                                                                               | 36.103.236\[.\]221  36.103.247\[.\]121 42.202.141\[.\]230 58.215.145\[.\]137 58.216.107\[.\]77 58.218.208\[.\]13 60.167.222\[.\]122 61.140.13\[.\]251 113.142.51\[.\]219 113.96.98\[.\]113 116.211.184\[.\]212 118.213.118\[.\]94 118.25.145\[.\]241 121.207.229\[.\]203 122.246.20\[.\]201 125.74.45\[.\]101 140.249.61\[.\]134 150.138.184\[.\]119 182.118.11\[.\]193 182.247.250\[.\]251 218.75.176\[.\]126 219.147.231\[.\]79 222.186.49\[.\]224                                                                                                                                                                                               |
| baocangwh\[.\]cn       | WHOIS Registration    | 4592248@qq\[.\]com                                                                                                                  | 103.52.216\[.\]35  104.18.38\[.\]253 104.18.39\[.\]253 104.31.92\[.\]26 104.31.93\[.\]26 119.28.48\[.\]240 205.185.122\[.\]229                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| z9ls\[.\]com           | WHOIS Registration    | 4592248@qq\[.\]com                                                                                                                  | 103.52.216\[.\]35  104.27.134\[.\]168 104.27.135\[.\]168 104.31.80\[.\]164 104.31.81\[.\]164 172.64.104\[.\]10 172.64.105\[.\]10 205.185.122\[.\]229                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| gwjyhs\[.\]com         | Hardcoded Domain      | gwjyhs\[.\]com                                                                                                                      | 103.52.216\[.\]35  104.27.138\[.\]191 104.27.139\[.\]191 205.185.122\[.\]229                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| heheda\[.\]tk          | Hardcode IP or Domain | 104.238.151.101  c.heheda\[.\]tk d.heheda\[.\]tk dd.heheda\[.\]tk                                                             | 104.18.58\[.\]79  104.18.59\[.\]79 104.238.151\[.\]101 195.20.40\[.\]95 198.204.231\[.\]250                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| cloudappconfig\[.\]com | Hardcode IP or Domain | 104.238.151.101  c.cloudappconfig\[.\]com img0.cloudappconfig\[.\]com Img1.cloudappconfig\[.\]com img2.cloudappconfig\[.\]com | 43.224.225\[.\]220  67.21.64\[.\]34 104.238.151\[.\]101 198.204.231\[.\]250                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| systemten\[.\]org      | Hardcoded Domain      | systemten\[.\]org                                                                                                                   | 104.248.53\[.\]213  104.31.92\[.\]233 104.31.93\[.\]233 134.209.104\[.\]20 165.22.156\[.\]147 185.193.125\[.\]146                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |

*Table 1. Known Rocke domains*

#### Rocke New Attack Vector

The TTPs listed in the previous section do not take into account a potential third stage to Rocke operations. Prior to the report [An Analysis of Godlua Backdoor](https://blog.netlab.360.com/an-analysis-of-godlua-backdoor-en/), Rocke malware appeared to perform a single operational function upon compromised cloud systems. The Godlua report cited malware samples that contained similar TTPs to those of Rocke. Upon further research, Unit 42 identified that not only do the TTPs match, but there are hardcoded domains, URLs, and an IP address that overlap with previously reported Rocke malware hardcoded values. This connection was made possible through the findings of an [incident investigation posting on the r/LinuxMalware subreddit](https://www.reddit.com/r/LinuxMalware/comments/bfaea2/fun_in_dissecting_lsd_packer_elf_golang_miner/) and the upload of the findings, including malware sample metadata, to [GitHub](https://gist.github.com/unixfreaxjp/d38a08ae7f41dc7ca5e9b16caa607cbe). The author of the Reddit post operates the nonprofit organization MalwareMustDie, a white hat organization devoted to the reduction of internet malware. Unit 42 researchers analyzed four of the binaries listed in the Reddit thread and confirmed the hardcoded Rocke domain systemten\[.\]org contained within the samples, which was stated in the Reddit thread. The samples also contained hardcoded links to the Pastebin URLs that overlap with known Rocke [reporting](https://www.anomali.com/blog/rocke-evolves-its-arsenal-with-a-new-malware-family-written-in-golang):

* hxxps://pastebin\[.\]com/raw/HWBVXK6H
* hxxps://pastebin\[.\]com/raw/60T3uCcb
* hxxps://pastebin\[.\]com/raw/rPB8eDpu
* hxxps://pastebin\[.\]com/raw/wR3ETdbi
* hxxps://pastebin\[.\]com/raw/Va86JYqw
* hxxps://pastebin\[.\]com/raw/Va86JYqw

As seen within the Godlua blog, the IP address 104.238.151\[.\]101 and the URLs d.heheda\[.\]tk, c.heheda\[.\]tk, and dd.heheda\[.\]tk were found to be hardcoded within the report's findings. The incident response thread posted to Reddit pertaining to the Rocke group also found that C2 connections were being sent to the three heheda\[.\]tk domains, which resolved to the IP address 104.238.151\[.\]101, also cited in the Godlua report. Additionally, the samples contained hardcoded values for the known Rocke domains of sowcar\[.\]com, z9ls\[.\]com, baocangwh\[.\]cn, gwjyhs\[.\]com, and w2wz\[.\]cn. See Figure 1 for how the identified indicators of compromise (IoCs) connect known Rocke domains with the IoCs pulled from the Godlua and Reddit thread IoC reporting.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/07/word-image-46.png)*Figure 1. Rocke domain connections to Godlua and Reddit thread reporting*

What makes the Godlua samples intriguing is the evidence that Rocke has added DoS operations to the group's toolkit. The report delivers evidence that Rocke has added a third-stage malware component that performs a third C2 request to either c.heheda\[.\]tk or c.cloudappconfig\[.\]com and thereby downloads a LUA script called Godlua. The malware appears to provide a modular functionality to Rocke's operational playbook. In addition to the DoS feature, the malware introduces the following new features:

* HANDSHAKE
* HEARTBEAT
* LUA
* SHELL
* UPGRADE
* QUIT
* SHELL2
* PROXY

The Godlua report also provided evidence that Rocke has added LUA switch functionality. The report states actors performed a DoS attack against the domain www.liuxiaobei\[.\]com. At the time of this writing, this domain does not resolve to any known system. It is currently unknown what functionality the other features of the Stage 3 malware accomplish. However, with options like "Shell," "Shell2," "Upgrade," and "Proxy," it is possible this malware is the beginning of a modular system agent that allows Rocke actors additional flexibility to perform cyber operations outside of cryptomining or data destruction.

#### Finding Rocke in the NetFlow

As of the time of this writing, Unit 42 researchers found 28.1% of cloud environments surveyed had at least one active communication session with known Rocke C2 domains. These connections occurred almost daily in some organizations from at least December 2018 until the time of this writing. Identification was made possible via the capture of NetFlow communications at the organization/cloud edge.

Unit 42 researchers discovered Rocke communications by analyzing Rocke's TTP patterns, resolving the known Rocke domains to IP addresses used during the specified timeframe, and querying network traffic against these resolved IP address as well as the hardcoded IP address linked to Rocke, 104.238.151\[.\]101.

Hardcoded IP addresses provide strong connections to known malicious network traffic originating from an organization's network. At the time of this writing, 104.238.151\[.\]101 is known to have resolved to the following URLs since January 1, 2019:

* c.cloudappconfig\[.\]com
* d.cloudappconfig\[.\]com
* f.cloudappconfig\[.\]com
* img0.cloudappconfig\[.\]com
* img2.cloudappconfig\[.\]com
* v.cloudappconfig\[.\]com
* c.heheda\[.\]tk
* d.heheda\[.\]tk
* dd.heheda\[.\]tk

These URLs are consistent with those reported in both the Godlua and Reddit reporting, signifying that any connection to this IP address should be considered malicious. Unit 42 researchers identified 411 unique connections from four monitored organizations that made eight or more fully established network connections to the IP address 104.238.151\[.\]101. These connections only persisted with each organization for a short period of time. The longest delta between first-seen connection and last-seen connection was five days for Organization 1. The shortest delta resulting in a single connection was one hour for Organization 4 (see Table 2).

|------------------|---------------------|-----------------------|-------------------|------------------|
| **Organization** | **Destination IP**  | **Total Connections** | **Earliest Time** | **Latest Time**  |
| 1                | 104.238.151\[.\]101 | 76                    | 4/12/19 3:00 AM   | 4/17/19 8:00 AM  |
| 2                | 104.238.151\[.\]101 | 160                   | 4/13/19 7:00 AM   | 4/15/19 3:00 PM  |
| 3                | 104.238.151\[.\]101 | 167                   | 4/13/19 7:00 AM   | 4/16/19 10:00 AM |
| 4                | 104.238.151\[.\]101 | 8                     | 5/10/19 9:00 PM   | 5/10/19 9:00 PM  |

*Table 2. Organization connections to hardcoded IP 104.238.151\[.\]101*

Extrapolating from 104.238.151\[.\]101, these four organizations also connected to other known Rocke domains. Organization 1 connected to three Rocke domains between April 12 and May 31, 2019, with 290 unique connections. Organization 4 connected to seven domains between March 20 and May 15, 2019, with 8,231 unique connections. As is evident in Table 3, the four organizations connect to one or more of the seven known Rocke domains during the same timeframe as the organization's connections to the hardcoded IP address 104.238.151\[.\]101. This strongly favors the connection between the domains heheda\[.\]tk and cloudappcloudconfig\[.\]com as Rocke domains and the usage of Rocke's third-stage malware being available during this same time period.

|------------------|--------------------------------------------------------|-------------------------|-----------------------|-------------------|------------------|
| **Organization** | **Destination Domain**                                 | **Destination IP**      | **Total Connections** | **Earliest Time** | **Latest Time**  |
| 1                | **Heheda\[.\]tk |**  **cloudappconfig\[.\]com** | **104.238.151\[.\]101** | 76                    | 4/12/19 3:00 AM   | 4/17/19 8:00 AM  |
|                  | sowcar\[.\]com                                         | 125.74.45\[.\]101       | 4                     | 4/12/19 2:00 PM   | 4/12/19 2:00 PM  |
|                  |                                                        | 27.221.54\[.\]252       | 2                     | 4/13/19 4:00 AM   | 4/13/19 4:00 AM  |
|                  | systemten\[.\]org                                      | 104.248.53\[.\]213      | 202                   | 4/10/19 12:00 PM  | 5/31/19 6:00 PM  |
|                  | w2wz\[.\]cn                                            | 113.96.98\[.\]113       | 2                     | 4/12/19 2:00 PM   | 4/12/19 2:00 PM  |
|                  |                                                        | 125.74.45\[.\]101       | 4                     | 4/12/19 2:00 PM   | 4/12/19 2:00 PM  |
| ***1 Total***    |                                                        |                         | ***290***             |                   |                  |
| 2                | baocanwh\[.\]cn                                        | 104.31.92\[.\]26        | 8                     | 4/25/19 3:00 AM   | 4/25/19 3:00 AM  |
|                  | heheda\[.\]tk                                          | 104.18.58\[.\]79        | 26                    | 4/14/19 6:00 AM   | 4/15/19 3:00 PM  |
|                  | heheda\[.\]tk                                          | 104.18.59\[.\]79        | 22                    | 4/14/19 6:00 AM   | 4/15/19 2:00 PM  |
|                  | **Heheda\[.\]tk** |  **cloudappconfig\[.\]com** | **104.238.151\[.\]101** | 160                   | 4/13/19 7:00 AM   | 4/15/19 2:00 PM  |
|                  | sowcar\[.\]com                                         | 104.31.68\[.\]79        | 77                    | 3/20/19 11:00 PM  | 4/3/19 4:00 AM   |
|                  |                                                        | 104.31.69\[.\]79        | 70                    | 3/20/19 7:00 AM   | 4/10/19 9:00 AM  |
|                  |                                                        | 125.74.45\[.\]101       | 6                     | 4/12/19 1:00 PM   | 4/12/19 2:00 PM  |
|                  |                                                        | 27.221.54\[.\]252       | 6                     | 4/13/19 4:00 AM   | 4/13/19 4:00 AM  |
|                  | systemten\[.\]org                                      | 104.248.53\[.\]213      | 92                    | 4/11/19 5:00 PM   | 4/15/19 3:00 PM  |
|                  | w2wz\[.\]cn                                            | 113.96.98\[.\]113       | 9                     | 4/12/19 2:00 PM   | 4/12/19 6:00 PM  |
|                  |                                                        | 122.246.20\[.\]201      | 8                     | 4/22/19 7:00 AM   | 4/22/19 8:00 AM  |
|                  |                                                        | 125.74.45\[.\]101       | 6                     | 4/12/19 1:00 PM   | 4/12/19 2:00 PM  |
|                  | z9ls\[.\]com                                           | 104.31.80\[.\]164       | 2                     | 4/14/19 11:00 AM  | 4/14/19 11:00 AM |
|                  |                                                        | 104.31.81\[.\]164       | 4                     | 4/15/19 3:00 AM   | 4/15/19 1:00 PM  |
| ***2 Total***    |                                                        |                         | ***496***             |                   |                  |
| 3                | heheda\[.\]tk                                          | 104.18.58\[.\]79        | 14                    | 4/14/19 11:00 AM  | 4/16/19 10:00 AM |
|                  | heheda\[.\]tk                                          | 104.18.59\[.\]79        | 14                    | 4/14/19 11:00 AM  | 4/16/19 10:00 AM |
|                  | **Heheda\[.\]tk** |  **cloudappconfig\[.\]com** | **104.238.151\[.\]101** | 167                   | 4/13/19 7:00 AM   | 4/16/19 10:00 AM |
|                  | sowcar\[.\]com                                         | 104.31.68\[.\]79        | 2                     | 4/10/19 9:00 AM   | 4/10/19 9:00 AM  |
|                  | systemten\[.\]org                                      | 104.248.53\[.\]213      | 214                   | 4/10/19 9:00 AM   | 4/19/19 9:00 AM  |
|                  | z9ls\[.\]com                                           | 104.31.80\[.\]164       | 106                   | 4/14/19 9:00 AM   | 4/18/19 3:00 AM  |
|                  |                                                        | 104.31.81\[.\]164       | 108                   | 4/14/19 9:00 AM   | 4/18/19 3:00 AM  |
| ***3 Total***    |                                                        |                         | ***625***             |                   |                  |
| 4                | baocanwh\[.\]cn                                        | 104.18.38\[.\]253       | 136                   | 4/26/19 9:00 PM   | 4/27/19 3:00 PM  |
|                  |                                                        | 104.18.39\[.\]253       | 152                   | 4/26/19 10:00 PM  | 4/28/19 3:00 AM  |
|                  |                                                        | 104.31.92\[.\]26        | 184                   | 4/22/19 9:00 AM   | 4/26/19 6:00 PM  |
|                  |                                                        | 104.31.93\[.\]26        | 170                   | 4/22/19 9:00 AM   | 4/26/19 6:00 PM  |
|                  |                                                        | 119.28.48\[.\]240       | 176                   | 4/27/19 1:00 PM   | 4/28/19 10:00 AM |
|                  | gwjyhs\[.\]com                                         | 104.27.138\[.\]191      | 256                   | 4/28/19 11:00 AM  | 5/9/19 10:00 AM  |
|                  |                                                        | 104.27.139\[.\]191      | 256                   | 4/28/19 10:00 AM  | 5/12/19 5:00 PM  |
|                  | **Heheda\[.\]tk** |  **cloudappconfig\[.\]com** | **104.238.151\[.\]101** | 8                     | 5/10/19 9:00 PM   | 5/10/19 9:00 PM  |
|                  | sowcar\[.\]com                                         | 104.31.68\[.\]79        | 437                   | 3/20/19 7:00 AM   | 4/10/19 2:00 AM  |
|                  |                                                        | 104.31.69\[.\]79        | 441                   | 3/20/19 2:00 PM   | 4/10/19 2:00 AM  |
|                  |                                                        | 27.221.54\[.\]252       | 8                     | 4/13/19 4:00 AM   | 4/13/19 4:00 AM  |
|                  | systemten\[.\]org                                      | 104.31.93\[.\]233       | 4                     | 4/5/19 2:00 AM    | 4/5/19 3:00 AM   |
|                  |                                                        | 104.31.92\[.\]233       | 4                     | 4/5/19 2:00 AM    | 4/5/19 3:00 AM   |
|                  |                                                        | 104.248.53\[.\]213      | 4761                  | 4/3/19 4:00 AM    | 5/15/19 1:00 AM  |
|                  | thyrsi\[.\]com                                         | 103.52.216\[.\]35       | 178                   | 4/27/19 8:00 AM   | 5/10/19 1:00 PM  |
|                  | w2wz\[.\]cn                                            | 118.25.145\[.\]241      | 12                    | 4/13/19 5:00 AM   | 4/13/19 9:00 AM  |
|                  | z9ls\[.\]com                                           | 104.31.80\[.\]164       | 522                   | 4/13/19 9:00 AM   | 4/21/19 2:00 PM  |
|                  |                                                        | 104.31.81\[.\]164       | 526                   | 4/13/19 6:00 AM   | 4/21/19 2:00 PM  |
| ***4 Total***    |                                                        |                         | ***8231***            |                   |                  |
| **Grand Total**  |                                                        |                         | **9642**              |                   |                  |

*Table 3. Comparison of all Rocke domain connections with IP 104.238.151\[.\]101*

Unit 42 researchers extrapolated the investigation another level and identified all visible connections from all monitored organizations to all known Rocke domains. The researchers found that 28.1% of cloud environments contained at least one fully established network connection with a known Rocke domain. The earliest witnessed connection took place on December 4, 2018, and continued through at least June 10, 2019, with 146 unique connections to the domains sowcar\[.\]com and w2wz\[.\]cn during that time frame.

#### Rocke's Network Traffic Pattern

Finally, Unit 42 researchers attempted to identify if the initial payload downloaded from Pastebin could be identified with the NetFlow data. Researchers found that a total of 50 organizations made network connections to Pastebin. Of these 50 organizations, eight were found to have made network connections to Pastebin within the same hour as connections to Rocke domains. Since NetFlow traffic only allows for a granularity capability of one hour, and given the lack of full packet capture to confirm the nature of the network connection, it is impossible to positively identify precisely what time an organization was compromised. However, these occurrences point to key timeframes where full packet captures, if available, should be investigated further.

A distinct pattern emerges when viewing how Rocke network traffic appears within NetFlow data (see Figure 2). First, a connection is established with Pastebin, followed by a connection to a Rocke domain. As you can see from the image, the pattern repeats on an hourly basis, which is another indicator of beaconing capabilities and of the presence of the Stage 3 Rocke payload, which is already installed on the cloud system. Additionally, Figure 2 displays the unique occurrence of the source system connecting to Pastebin, then connecting to the known Rocke domains, z9ls\[.\]com, and systemten\[.\]org, connecting to the hardcoded IP address 104.238.151\[.\]101 in the same time frame. This pattern is indicative of a beaconing, or a heartbeat style of activity, which is a capability within the third-stage malware's feature set.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/07/word-image-47.png)*Figure 2. Unique Rocke NetFlow pattern*

#### Mitigation Strategies

To mitigate Rocke activities within a cloud environment, the following actions are recommended:

* Update all cloud system templates with the latest patches and version updates.
* Cycle all cloud systems to use the latest patched and updated cloud template.
* Purchase and configure a cloud monitoring product that includes checks on compliance, network traffic, and user behavior.
* Review cloud network configurations, security policies, and groups to ensure they meet current compliance requirements.
* Use a cloud container vulnerability scanner.
* Update all threat intelligence feeds providing domain or IP denylisting indicators.
* Purchase or subscribe to Palo Alto Networks MineMeld threat feed, or use Palo Alto Networks Next-Generation Firewalls, as these options are configured to block known Rocke domains and IP connections.
* Investigate cloud network traffic for connections to known malicious domains or IPs.
* Investigate cloud network traffic for beacon-style egress traffic in your organization's cloud environment.

### Conclusion

Rocke, which primarily targets public cloud infrastructure for criminal gain, continues to evolve its tools and take advantage of poorly configured cloud infrastructures using vulnerabilities released in 2016 and 2017. The group can gain administrative access to cloud systems using malware that is able to remain hidden from basic investigations. Compromised systems then perform predictable and detectable network actions to known Rocke hardcoded IP addresses or Rocke-owned domains.

Palo Alto Networks customers are protected as follows:

* The C2 domains listed in this blog are identified as malicious by our PAN-DB URL Filtering.
* All illegitimate tools uploaded to the webshells are identified as malicious by WildFire and Traps.
* ELF and PE format malware signatures have been released via antivirus.
* All C2 domains have been covered by PAN-DB URL Filtering.

AutoFocus customers can investigate this activity with the following tags:

* [IronCybercrimeGroup](https://autofocus.paloaltonetworks.com/#/tag/Unit42.IronCybercrimeGroup)
* [Xbash](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Xbash)
* [Kerberods](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Kerberods)
* [Godlua](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Godlua)

Palo Alto Networks has shared our findings, including file samples and indicators of compromise, in this report with our fellow Cyber Threat Alliance members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. For more information on the Cyber Threat Alliance, visit [www.cyberthreatalliance.org](https://www.cyberthreatalliance.org/).

#### Indicators of Compromise

#### Domains

sowcar\[.\]com

thyrsi\[.\]com

w2wz\[.\]cn

baocangwh\[.\]cn

z9ls\[.\]com

gwjyhs\[.\]com

heheda\[.\]tk

cloudappconfig\[.\]com

systemten\[.\]org

#### IPs

43\.224.225\[.\]220

67\.21.64\[.\]34

103\.52.216\[.\]35

104\.248.53\[.\]213

104\.238.151\[.\]101

198\.204.231\[.\]250

205\.185.122\[.\]229

#### Hashes

1608899ff3bd9983df375fd836464500f160f6305fcc35cfb64abbe94643c962

28f92f36883b69e281882f19fec1d89190e913a4e301bfc5d80242b74fcba6fe

a84283095e0c400c3c4fe61283eca6c13dd0a6157a57adf95ae1dcec491ec519

6797018a6f29ce3d447bd3503372f78f9513d4648e5cd3ab5ab194a50c72b9c4

Back to top

### Tags

* [Cloud Malware Agent](https://unit42.paloaltonetworks.com/tag/cloud-malware-agent/ "Cloud Malware Agent")
* [NetFlow](https://unit42.paloaltonetworks.com/tag/netflow/ "NetFlow")
* [Rocke](https://unit42.paloaltonetworks.com/tag/rocke/ "Rocke")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Unveiling 11 New Adversary Playbooks](https://unit42.paloaltonetworks.com/unveiling-11-new-adversary-playbooks/ "Unveiling 11 New Adversary Playbooks")

### Related Articles

* [A Look Into Public Clouds From the Ransomware Actor's Perspective](https://unit42.paloaltonetworks.com/ransomware-in-public-clouds/ "article - table of contents")
* [IAM Your Defense Against Cloud Threats: The Latest Unit 42 Cloud Threat Research](https://unit42.paloaltonetworks.com/iam-cloud-threat-research/ "article - table of contents")
* [Pro-Ocean: Rocke Group's New Cryptojacking Malware](https://unit42.paloaltonetworks.com/pro-ocean-rocke-groups-new-cryptojacking-malware/ "article - table of contents")

## Related Resources

![Pictorial representation of automated detection. Digital illustration of a glowing blue brain connected to a network of lines and lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Cloud_cybersecurity_research_Overview_1920x900-2-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 14, 2026 [#### Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection](https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/)

* [AWS CloudTrail](https://unit42.paloaltonetworks.com/tag/aws-cloudtrail/ "AWS CloudTrail")

* [Cloud detection](https://unit42.paloaltonetworks.com/tag/cloud-detection/ "cloud detection")

* [DevOps](https://unit42.paloaltonetworks.com/tag/devops/ "DevOps")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/ "Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection")  
  ![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of bucket hijacking technique for cloud data exfiltration. Digital illustration of Europe map highlighting network connections and nodes, depicted as glowing points and lines on a dark blue background, emphasizing major cities and connectivity across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/09_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 22, 2026 [#### The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/)

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")

* [Bucket hijacking](https://unit42.paloaltonetworks.com/tag/bucket-hijacking/ "bucket hijacking")

* [Cloud data exfiltration](https://unit42.paloaltonetworks.com/tag/cloud-data-exfiltration/ "cloud data exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/ "The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration")  
  ![Pictorial representation of Vertex AI model uploads. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_1270203474-1-786x354.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 16, 2026 [#### Pickle in the Middle -- Hijacking Vertex AI Model Uploads for Cross-Tenant RCE](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/)

* [Bucket squatting](https://unit42.paloaltonetworks.com/tag/bucket-squatting/ "bucket squatting")

* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")

* [Joblib](https://unit42.paloaltonetworks.com/tag/joblib/ "joblib")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/ "Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE")  
  ![Pictorial representation of Cloud Logging services for defense evasion. A vibrant digital illustration depicting a glowing, neon blue cloud symbol positioned over a circuit board landscape. The cloud symbolizes cloud computing technology, and the landscape features intricate electronic circuits with glowing lines and nodes, suggesting high-tech data transfer and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 9, 2026 [#### Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility](https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/)

* [AWS CloudTrail](https://unit42.paloaltonetworks.com/tag/aws-cloudtrail/ "AWS CloudTrail")

* [Cloud logging](https://unit42.paloaltonetworks.com/tag/cloud-logging/ "cloud logging")

* [Defense evasion](https://unit42.paloaltonetworks.com/tag/defense-evasion/ "defense evasion")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/ "Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of ROADtools framework in the cloud. An Asian man wearing glasses sits in front of a computer screen. Reflecting in the glasses are lines indicating analysis. Bright blue city lights illuminate the rest of the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/10_Cloud_cybersecurity_research_Overview_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) May 22, 2026 [#### Paved With Intent: ROADtools and Nation-State Tactics in the Cloud](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/)

* [Curious Serpens](https://unit42.paloaltonetworks.com/tag/curious-serpens/ "Curious Serpens")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/ "Paved With Intent: ROADtools and Nation-State Tactics in the Cloud")  
  ![Pictorial representation of autonomous AI attack in cloud environments. Digital illustration of a glowing blue brain connected to a network of lines and lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/12_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 23, 2026 [#### Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Cloud](https://unit42.paloaltonetworks.com/tag/cloud/ "Cloud")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/ "Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System")  
  ![Pictorial representation of passwordless authentication. Futuristic cityscape with skyscrapers surrounded by glowing, neon-lit pathways and digital clouds. The sky is vibrant with pink and orange hues, giving a surreal, cyberpunk aesthetic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/02_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 23, 2026 [#### Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication/)

* [Google](https://unit42.paloaltonetworks.com/tag/google/ "Google")

* [Google authenticator](https://unit42.paloaltonetworks.com/tag/google-authenticator/ "google authenticator")

* [Google Chrome](https://unit42.paloaltonetworks.com/tag/google-chrome/ "Google Chrome")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/passwordless-authentication/ "Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
