Lemon Duck is a financially motivated cryptocurrency-mining botnet and malware operation known for rapidly incorporating newly disclosed vulnerabilities into its intrusion playbook. It is best known for opportunistic exploitation of unpatched Microsoft Exchange Server systems during the 2021 ProxyLogon period, where it used both web-shell-based access and fileless execution via direct PowerShell launched from IIS worker processes. The operation has also been associated with modular, self-propagating behavior and continued expansion of exploit capabilities over time. Lemon Duck commonly combines living-off-the-land techniques with post-compromise automation. Observed tradecraft includes PowerShell-based payload delivery, use of CertUtil and WMI, scheduled-task persistence, WMI event subscription persistence, disabling or uninstalling security products, modifying firewall settings, and removing competing malware from infected hosts. On compromised Exchange servers it has deployed web shells, including variants consistent with China Chopper-style functionality, created privileged local accounts, enabled remote access mechanisms such as RDP, and performed follow-on activity to preserve exclusive control of victim systems. The operation has been observed deploying XMRig mining payloads and secondary tooling including Cobalt Strike DNS beacons, remote-access tools, and information-stealing malware. Microsoft also reported that Lemon Duck downloaded additional payloads for lateral movement and credential theft, and abused compromised Exchange mail servers to access mailboxes and send malicious email carrying its payloads. The actor has used DNS-based command-and-control concealment and hosts-file manipulation with decoy East Asian-themed domains as part of its defense-evasion and obfuscation strategy. Lemon Duck is not a ransomware actor in the reported activity; its dominant objective is monetization through cryptomining and related criminal post-exploitation. No high-confidence attribution to a nation state is established in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
63 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.