LemonDuck is a financially motivated cryptocurrency-mining botnet and malware operation first publicly observed in 2019. It is known for opportunistic exploitation of poorly managed and internet-exposed systems, and has evolved from spam-delivered cryptomining malware into a more capable intrusion platform affecting both Windows and Linux environments. Commonly associated aliases include LemonDuck and lemon_duck. LemonDuck has targeted exposed enterprise services and servers, including Microsoft Exchange, Microsoft SQL Server, Hadoop, Redis, SMB, RDP, and HTTP File Server. It has been observed exploiting high-profile vulnerabilities such as the ProxyLogon-era Microsoft Exchange flaws and later HFS remote code execution, as well as using brute-force and dictionary attacks against exposed services. The malware also self-propagates across networks and has historically incorporated exploit capabilities associated with SMB worming. Its tradecraft emphasizes living-off-the-land execution and operational resilience. Observed techniques include PowerShell-based payload delivery, direct command execution from IIS worker processes, use of CertUtil and WMI, scheduled tasks, WMI event subscription persistence, firewall modification, Remote Desktop enablement, local account creation, and abuse of SQL Server features such as xp_cmdshell and CLR stored procedures. LemonDuck has been observed dropping web shells on compromised Exchange servers, using DNS-based command-and-control through Cobalt Strike beacons, modifying hosts files with decoy entries, and removing artifacts after execution. The operation routinely disables or uninstalls security products, turns off defensive controls, removes competing malware, and in some cases patches compromised servers to block rival attackers while preserving its own access. Beyond cryptomining payloads such as XMRig, LemonDuck has also deployed secondary malware including information stealers and remote-access tooling, and has been observed abusing compromised Exchange infrastructure to access mailboxes and send malicious email. Reporting also indicates credential collection, lateral movement tooling, and hands-on-keyboard post-compromise activity, suggesting an evolution beyond purely automated mining. LemonDuck’s dominant objective remains illicit cryptocurrency mining and monetization of compromised infrastructure rather than ransomware. Although it has shown post-exploitation depth comparable to broader cybercrime intrusion sets, high-confidence reporting characterizes it primarily as a cybercriminal botnet focused on financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
In May 2024, a remote code execution vulnerability (CVE-2024-23692) in HFS was announced... the Proof of Concept (PoC) was announced... threat actor can exploit the CVE-2024-23692 vulnerability after scanning the externally exposed HFS service to install malware or obtain control.
63 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploits the HFS RCE (CVE-2024-23692) to compromise exposed HFS servers, run discovery commands, create/enable hidden local accounts for RDP access, and deploy coin-mining and additional tooling (XMRig, plus XenoRAT and a vulnerability-scanner script).
Uses MS-SQL server brute-force/dictionary attacks (and lateral movement) and then leverages MS-SQL OS command execution features (e.g., xp_cmdshell and CLR Stored Procedures) to download/install additional payloads (e.g., coin miners, other malware).
A crypto-mining botnet operation that evolved into a large, persistent campaign and is now experimenting with hands-on-keyboard intrusions after compromising networks. It spreads via spam and web-based attacks, targets exposed services and unpatched servers, steals credentials, disables security tools, moves laterally, removes competing malware, and has begun deploying additional malware on infected systems.
Cryptocurrency-mining botnet operators targeting unpatched Microsoft Exchange servers, exploiting ProxyLogon-era Exchange vulnerabilities, deploying web shells, using Cobalt Strike DNS beacons, disabling security tools, establishing persistence, and conducting post-compromise reconnaissance and account creation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.