LemonDuck is a threat actor and associated coin-mining malware operation first discovered in 2019. The provided content identifies it as one of at least four threat actors exploiting HTTP File Server (HFS) CVE-2024-23692 to compromise exposed systems and install XMRig Monero miners. In the observed HFS exploitation activity, LemonDuck-associated intrusions also installed XenoRAT and a vulnerability-scanner script. The content states LemonDuck has exploited various vulnerabilities to attack poorly managed systems. The actor is also linked to attacks against poorly managed, internet-exposed Microsoft SQL Server environments. The content describes LemonDuck using scanning and brute-force or dictionary attacks against weak MS-SQL credentials, as well as self-propagation to poorly managed MS-SQL servers. LemonDuck is specifically noted as using xp_cmdshell and CLR Stored Procedures, including re-registering xp_cmdshell if it is unregistered. A LemonDuck-related SqlShell example, evilclr.dll, provides command execution via an ExecCommand() method. Across the described activity, LemonDuck is associated with post-compromise command execution and staging of coin-miner deployment, particularly XMRig/Monero mining. No additional aliases or sub-groups are provided in the content beyond "lemonduck".
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploits the HFS RCE (CVE-2024-23692) to compromise exposed HFS servers, run discovery commands, create/enable hidden local accounts for RDP access, and deploy coin-mining and additional tooling (XMRig, plus XenoRAT and a vulnerability-scanner script).
Uses MS-SQL server brute-force/dictionary attacks (and lateral movement) and then leverages MS-SQL OS command execution features (e.g., xp_cmdshell and CLR Stored Procedures) to download/install additional payloads (e.g., coin miners, other malware).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.