s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.pro_ocean

📛 Threat Title

Malware family: Pro-Ocean

Category: Pro-Ocean First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.pro_ocean`. Printable name: Pro-Ocean.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (8)

  • web:malpedia.caad.fkie.fraunhofer.de

    elf. pro_ocean (Back to overview) Pro-Ocean Propose Change Actor (s): Rocke Unit 42 describes this as a malware used by Rocke Group that deploys an XMRig miner.

  • web:sechub.in

    The malware is known as " Pro Ocean ," first detected in 2019, and now includes "worm" features and the detection-evasion features of rootkits. For cloud apps, Pro-Ocean utilizes well-known vulnerabilities Pro-Ocean attacked Apache ActiveMQ, Oracle WebLogic (CVE-2017-10271), and Redis in their study.

  • web:support.trellix.com

    Summary Description of Campaign Pro-Ocean cryptojacking malware is attributed to the Rocke Group threat group and targets cloud applications with unsecure instances or known vulnerabilities. The malicious software has been observed focusing on Apache ActiveMQ, Oracle WebLogic, and Redis servers. Multiple obfuscation layers are used to disguise itself including software packing, deleting the ...

  • web:unit42.paloaltonetworks.com

    Pro-Ocean is a revised version of cloud-targeted cryptojacking malware , which now includes new and improved rootkit and worm capabilities.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.microsoft.com

    Submit a file for malware analysis Microsoft security researchers analyze suspicious files to determine if they are threats, unwanted applications, or normal files. Submit files you think are malware or files that you believe have been incorrectly classified as malware . For more information, read the submission guidelines.

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

  • web:www.pcrisk.com

    In 2025 and early 2026, law enforcement and cybersecurity agencies in the United States have sounded repeated alarms over the rise of sophisticated ATM "jackpotting" attacks, incidents in which threat actors use malware and physical access to force automated teller machines to dispense cash illegally. The phenomenon has cost financial institutions tens of millions of dollars and prompted an ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.