LemonDuck, also written as Lemon Duck or lemon_duck, is a financially motivated cybercriminal operation associated with a modular, self-propagating cryptocurrency-mining botnet first observed in 2019. It compromises Windows and Linux systems, primarily to deploy Monero miners such as XMRig, while also stealing credentials, establishing persistent access, and installing additional malware. Its activity is geographically widespread, including infections in India. Initially distributed through malicious email attachments, LemonDuck expanded to vulnerability exploitation and brute-force attacks against exposed Microsoft Exchange, Microsoft SQL Server, Hadoop, Redis, SMB, and RDP services. Its exploitation capabilities include EternalBlue, SMBGhost, and the Exchange vulnerabilities CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. LemonDuck has also compromised vulnerable HTTP File Server installations in activity associated with CVE-2024-23692. On SQL Server, it abuses xp_cmdshell and CLR stored procedures for command execution. LemonDuck uses obfuscated, multistage PowerShell scripts and legitimate administrative utilities to execute payloads, collect system information, disable security controls, and spread laterally. Persistence mechanisms include scheduled tasks, WMI event subscriptions, web shells, and accounts configured for remote access. Some Exchange attacks execute PowerShell directly through the IIS worker process without deploying a web shell. Additional tooling includes Cobalt Strike DNS beacons, XenoRAT, and Ramnit. Operators have also conducted hands-on-keyboard activity and abused compromised Exchange mailboxes to distribute malicious emails. A distinctive operational behavior is removing competing miners and other attackers' artifacts. LemonDuck sometimes patches exploited systems to prevent rivals from regaining access while retaining its own foothold. It also obscures command-and-control traffic through DNS communications and local hostname mappings. Its documented operations center on illicit cryptocurrency mining and broader post-compromise access; ransomware deployment has not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
2024년 5월 HFS의 원격 코드 실행 취약점인 CVE-2024-23692가 공개되었으며 이를 활용할 경우 공격자는 HFS에 명령이 포함된 패킷을 전송하여 HFS가 악성 명령을 실행하도록 할 수 있다.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
63 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a historical example of cryptojacking operators removing competing mining software. The content does not attribute the observed CVE-2024-4577 exploitation or firewall modifications to LemonDuck.
LemonDuck is identified as one of at least four actors attacking vulnerable HTTP File Server (HFS) installations to deploy cryptocurrency miners. First observed in 2019, it exploits vulnerabilities in poorly managed systems. The described operation installs XMRig to mine Monero, alongside XenoRAT and a vulnerability-scanning script.
Exploits the HFS RCE (CVE-2024-23692) to compromise exposed HFS servers, run discovery commands, create/enable hidden local accounts for RDP access, and deploy coin-mining and additional tooling (XMRig, plus XenoRAT and a vulnerability-scanner script).
Uses MS-SQL server brute-force/dictionary attacks (and lateral movement) and then leverages MS-SQL OS command execution features (e.g., xp_cmdshell and CLR Stored Procedures) to download/install additional payloads (e.g., coin miners, other malware).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.