LemonDuck is an actively maintained cross-platform malware family and botnet best known for cryptocurrency mining, particularly Monero mining via XMRig, but it has evolved well beyond a simple coinminer. Since first being observed in 2019, it has developed into a multifunctional intrusion platform that combines automated propagation with post-compromise tradecraft, including credential theft, lateral movement, security-tool removal, persistence, and delivery of secondary payloads. It has been associated with both broad spray-and-pray activity and more selective hands-on-keyboard follow-on operations.
LemonDuck targets Windows and Linux systems and has been observed abusing a wide range of exposed or weakly protected services, including SMB, RDP, SSH, Microsoft Exchange, MSSQL, Redis, and Hadoop YARN. It spreads through phishing email campaigns, exploitation of known vulnerabilities, brute-force attacks, USB and attached-drive propagation, and lateral movement inside compromised environments. Campaigns have included exploitation of Microsoft Exchange ProxyLogon vulnerabilities as well as older flaws such as EternalBlue and other widely abused remote-access vulnerabilities.
On Windows, LemonDuck commonly relies on PowerShell-heavy, multi-stage infection chains and fileless or semi-fileless persistence through scheduled tasks, WMI event consumers, registry-based mechanisms, and startup persistence. It has been observed using WMI and PowerShell to modify Exchange Offline Address Book settings and deploy web-shell functionality for remote command execution. It also uses process injection and in-memory execution to complicate remediation. The malware attempts to disable or weaken Microsoft Defender, add broad exclusions, uninstall security products, and remove competing malware or miners from infected hosts. In some intrusions, operators have patched the same vulnerabilities they exploited in order to retain exclusive access and reduce interference from rival actors.
LemonDuck includes credential-access and post-exploitation functionality, including use of bundled Mimikatz components to steal credentials for reuse and lateral movement. It performs reconnaissance and scanning, attempts logons against adjacent systems, abuses SMB for propagation and covert file transfer, and can self-spread through Outlook by harvesting contacts and sending malicious attachments from compromised mailboxes. It also propagates through removable and network-connected drives by planting hidden malicious files.
Operationally, LemonDuck has been described as having at least two related infrastructures, sometimes referred to as Duck and Cat. The Cat-associated activity has been linked to more dangerous post-compromise outcomes, including backdoor installation, credential theft, data theft, and delivery of additional malware such as Ramnit. This evolution has made LemonDuck notable not only as a cryptomining threat but also as a loader and foothold that can enable broader enterprise compromise.
LemonDuck has had global reach, with significant activity observed across North America, Europe, and Asia. It should be treated as more than commodity mining malware because its combination of worm-like spread, defense evasion, credential theft, persistence, and follow-on payload delivery makes it a serious intrusion threat in enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In March and April 2021, various vulnerabilities related to the ProxyLogon set of Microsoft Exchange Server exploits were utilized by LemonDuck to install web shells and gain access to outdated systems. | Ensure that Linux and Windows devices are included in routine patching, and validate protection against the CVE-2019-0708, CVE-2017-0144, CVE-2017-8464, CVE-2020-0796, CVE-2021-26855, CVE-2021-26858, and CVE-2021-27065 vulnerabilities. | LemonDuck is an actively updated and robust malware primarily known for its botnet and cryptocurrency mining objectives. Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
In 2021, it exploited newly patched Exchange Server vulnerabilities to gain access to outdated systems... vulnerabilities like CVE-2021-27065 (ProxyLogon) | LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives... Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
In 2021, it exploited newly patched Exchange Server vulnerabilities to gain access to outdated systems... vulnerabilities like CVE-2021-26858 (ProxyLogon) | LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives... Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
the LemonDuck operators have leveraged scans against both Windows and Linux devices for open or weakly authenticated SMB, Exchange, SQL, Hadoop, REDIS, RDP, or other edge devices that might be vulnerable to password spray or application vulnerabilities like CVE-2017-0144 (EternalBlue) | LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives... Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
In 2021, it exploited newly patched Exchange Server vulnerabilities to gain access to outdated systems... vulnerabilities like CVE-2021-26857 (ProxyLogon) | LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives... Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
the LemonDuck operators have leveraged scans against both Windows and Linux devices for open or weakly authenticated SMB, Exchange, SQL, Hadoop, REDIS, RDP, or other edge devices that might be vulnerable to password spray or application vulnerabilities like CVE-2017-8464 (LNK RCE) | LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives... Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
the LemonDuck operators have leveraged scans against both Windows and Linux devices for open or weakly authenticated SMB, Exchange, SQL, Hadoop, REDIS, RDP, or other edge devices that might be vulnerable to password spray or application vulnerabilities like CVE-2019-0708 (BlueKeep) | LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives... Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
the LemonDuck operators have leveraged scans against both Windows and Linux devices for open or weakly authenticated SMB, Exchange, SQL, Hadoop, REDIS, RDP, or other edge devices that might be vulnerable to password spray or application vulnerabilities like CVE-2020-0796 (SMBGhost) | LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives... Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Today, the botnet can infect both Windows and Linux systems and comes equipped with a trove of features that allow it to... collect credentials from local systems to ensure future and more persistent access.
Other common methods of infection include movement within the compromised environment, as well as through USB and connected drives.
In 2021, it exploited newly patched Exchange Server vulnerabilities to gain access to outdated systems... vulnerabilities like CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 (ProxyLogon).
LemonDuck... capitalizes on the ProxyLogon bug to target systems, but its infection utilizes Windows Management Instrumentation (WMI) to modify the OAB.
These campaigns included PowerShell scripts that employed additional scripts kicked off by a scheduled task.
their multi-stage PowerShell scripts were more complex and obfuscated than others', and they already made extensive use of open-source tools for code execution and infection
These campaigns included PowerShell scripts... The JavaScript has replaced the scheduled task that LemonDuck previously used to kickstart the PowerShell script.
These campaigns included PowerShell scripts that employed additional scripts kicked off by a scheduled task.
Today, the botnet can infect both Windows and Linux systems and comes equipped with a trove of features that allow it to... collect credentials from local systems to ensure future and more persistent access.
Leveraging the ProxyLogon vulnerability allowed the threat actors behind BlackKingdom, Prometei, and LemonDuck to execute Chopper web shells... The China Chopper web shell... continues to be widely used by threat actors in their campaigns to gain remote access to a targeted system.
These campaigns included PowerShell scripts that employed additional scripts kicked off by a scheduled task.
These techniques also include utilizing process injection and in-memory execution, which can make removal non-trivial.
IF.Bin drops additional .BIN files to attempt common service exploits like CVE-2017-8464 ... to increase privilege.
Today, the botnet can infect both Windows and Linux systems and comes equipped with a trove of features that allow it to... collect credentials from local systems to ensure future and more persistent access.
we have observed a PowerShell process that executes a Base64-encoded command
These techniques also include utilizing process injection and in-memory execution, which can make removal non-trivial.
After the emails are sent, the inbox is cleaned to remove traces of these mails.
Today, the botnet can infect both Windows and Linux systems and comes equipped with a trove of features that allow it to... collect credentials from local systems to ensure future and more persistent access.
LemonDuck then attempts to automatically remove a series of other security products through CMD.exe, leveraging WMIC.exe.
It uses a wide range of spreading mechanisms—phishing emails, exploits, USB devices, brute force, among others... scans against both Windows and Linux devices for open or weakly authenticated SMB, Exchange, SQL, Hadoop, REDIS, RDP, or other edge devices that might be vulnerable to password spray
If all of those fail, LemonDuck also uses its access methods such as RDP, Exchange web shells, Screen Connect, and RATs to maintain persistent access.
Other common methods of infection include movement within the compromised environment, as well as through USB and connected drives.
The task was used to bring in the PCASTLE tool to achieve a couple of goals: abuse the EternalBlue SMB exploit...
Today, beyond using resources for its traditional bot and mining activities... ultimately drops more tools for human-operated activity... Today, the Cat infrastructure is used in attacks that typically result in backdoor installation... and malware delivery. It is often seen delivering the malware Ramnit.
Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls... Notably, LemonDuck removes other attackers from a compromised device by getting rid of competing malware and preventing any new infections by patching the same vulnerabilities it used to gain access.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to transfer malicious executables over SMB, create hidden administrative shares, deploy scripts and batch files for scheduled tasks, modify network configurations, download additional payloads, and support persistent cryptomining activity.
Cryptomining malware that exploits SMB, including EternalBlue, spreads via phishing, SMB exploitation, and brute-force attacks, disables defenses, establishes persistence with scheduled tasks, downloads additional payloads via PowerShell/mshta, and uses compromised resources for cryptojacking.
Cryptomining malware that propagates to poorly managed MS-SQL servers using dictionary attacks and leverages SQL Server OS-command execution (xp_cmdshell and CLR stored procedures) to download and run additional payloads.
A crypto-mining malware strain that evolved into a large botnet. It infects Windows and Linux systems, disables security software, spreads laterally, removes competing malware, patches infected servers against rivals, steals credentials, and has begun enabling hands-on-keyboard intrusions for more persistent and potentially more dangerous follow-on activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.