Lemon Duck is a modular Monero cryptomining malware and botnet known for combining fileless PowerShell tradecraft, in-memory execution, worm-like propagation, and broad post-compromise activity. Although primarily associated with cryptocurrency mining, it has repeatedly demonstrated capabilities beyond simple mining, including credential theft tooling, lateral movement, persistence, security-tool removal, and delivery of secondary payloads such as Cobalt Strike and information stealers.
Lemon Duck has targeted Windows systems extensively and has also been observed compromising Linux servers in Oracle WebLogic exploitation chains. It has been linked to attacks against unpatched Microsoft Exchange Server and Oracle WebLogic Server, and to opportunistic compromise of exposed enterprise services including SMB, RDP, SSH, Microsoft SQL Server, Redis, and Hadoop/Yarn. Campaigns have also used phishing lures, including coronavirus-themed emails, to gain initial access.
A defining characteristic of Lemon Duck is its heavy use of living-off-the-land techniques. It commonly executes obfuscated PowerShell, often through native processes such as the IIS worker process on compromised Exchange servers, and uses tools such as WMI, Task Scheduler, CertUtil, service creation utilities, and firewall or networking commands to establish persistence, disable defenses, and retrieve additional components. Persistence has been observed through scheduled tasks, WMI event subscriptions, malicious services, and creation of administrative local accounts with Remote Desktop enabled.
Propagation and lateral movement are central to Lemon Duck operations. Across campaigns it has used EternalBlue, SMBGhost, pass-the-hash, brute-force attacks against RDP, SSH, and MSSQL, exploitation of Exchange ProxyLogon vulnerabilities, exploitation of Oracle WebLogic CVE-2020-14882, compromise of Redis and Hadoop/Yarn services, and LNK-based spread via removable or network drives. It also scans internal networks for reachable services, especially SMB and MSSQL, to expand infections.
Post-exploitation behavior includes host reconnaissance, collection of system metadata, attempted dumping of password hashes, retrieval of Mimikatz-related tooling, and removal or disabling of competing miners and security products. Lemon Duck has been observed modifying Windows Defender settings, uninstalling antivirus products, altering firewall behavior, and using deceptive naming to disguise miner-related services as legitimate Microsoft components. Some campaigns also deployed China Chopper-style web shells on Exchange servers and used compromised mail infrastructure to send further malicious email.
Lemon Duck is best understood as a multi-capability intrusion platform centered on cryptomining revenue, but adaptable for broader access operations. Its evolution from a primarily cryptomining threat into one that also supports secondary payload delivery and deeper enterprise compromise has made it notable in attacks against internet-facing servers and poorly secured internal services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Description https://news.sophos.com/en-us/2021/05/07/new-lemon-duck-variants-exploiting-microsoft-exchange-server/ Indicators for Lemon_Duck malware (2021-05-07)
we continue to observe campaigns spreading the Lemon Duck cryptomining trojan via Coronavirus-themed phishing emails. Lemon Duck is a primarily “file-less” cryptomining trojan which is also able to spread via Eternalblue.
In March, Microsoft published a set of critical fixes to Exchange Server following the discovery of ProxyLogon—an exploit that was stolen or leaked from researchers within hours of its disclosure to Microsoft. The exploit is now widely available to cybercriminals... Recently, we discovered that ProxyLogon has been added to an update to Lemon Duck... | Recently, we discovered that ProxyLogon has been added to an update to Lemon Duck, an advanced crypto miner malware.
The attack exploits CVE-2020-14882, a remote code execution vulnerability, to download and execute a malicious script on vulnerable WebLogic servers. | Recently, we discovered that ProxyLogon has been added to an update to Lemon Duck, an advanced crypto miner malware.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world. | Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck cryptocurrency mining botnet that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons.
Lemon Duck operators have previously employed several exploits for vulnerabilities, such as SMBGhost and Eternal Blue, and appear to be implementing new exploit code and targeting additional software vulnerabilities over time. | Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck cryptocurrency mining botnet that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host. | Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck cryptocurrency mining botnet that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host. | Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck cryptocurrency mining botnet that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Lemon Duck’s miner tries to uninstall security product from the machine by using WMI (Windows Management Instrumentation).
it then creates a scheduled task called "syspstem" and configures it to execute it every 50 minutes
url_path hxxp://t.amynx.com/ln/a.asp?src_date_*whoami*hostname*guid Linux Core malicious shell script
url_path hxxp://t.amynx.com/7p.php?0.8*ipc*%username%*%computername%*+[Environment]::OSVersion.version.Major 2nd level malicious powershell component
We also witnessed an attempted file-less attack, in which the Lemon Duck actor sent commands... to be directly executed by the Windows command-line interface (cmd.exe), attempting to create a user and gain Remote Desktop access
it then creates a scheduled task called "syspstem" and configures it to execute it every 50 minutes
followed by several attempts to invoke "net localgroup" to add this newly created user to the following local security groups: administrators, Administrateurs, Remote Desktop Users and Enterprise Admins.
REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
it then creates a scheduled task called "syspstem" and configures it to execute it every 50 minutes
Additional obfuscation techniques are now being used to make the infrastructure associated with these campaigns more difficult to identify and analyze. The use of fake domains on East Asian top-level domains (TLDs) masks connections to the actual command and control (C2) infrastructure
later using the service controller to change the display name and description of this service as “Microsofts Defender Antivirus Network Inspection Service”.
Following execution of the cryptocurrency mining payload, the PowerShell script is responsible for cleaning up various artifacts and removing indicators of compromise, such as the aforementioned "dn.ps1" and "c.ps1" from the infected system.
In some cases, the use of certutil... to download the Lemon Duck payload... certutil was abused to download a PowerShell script.
the attacker began to copy the initially-dropped web shell to multiple different directories, and changed the attributes of the web shell files to make them hidden with read-only permission.
The Windows "attrib" command was also used to set the Archive file attribute, System file attribute, Read-only attribute, and the Hidden file attribute on the previously created files and directories, likely as a way to obfuscate the actor's activities on the system.
domain d.hwqloan.com; domain t.hwqloan.com; domain ps2.jusanrihua.com; domain t.amynx.com
This payload was configured as a Windows DNS beacon and attempts to communicate with the C2 server ... using a DNS-based covert channel.
The "netsh.exe" Windows command is also used to disable Windows Firewall settings, enable port forwarding, and redirect traffic to 1[.]1[.]1[.]1[:]53 from port 65529/TCP.
the attacker used certutil to download the malicious script and executables to the disk... In the first of those, certutil was abused to download a PowerShell script. In another variant, the attackers used certutil to directly download a compiled Python executable payload
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Primarily fileless cryptomining trojan spread via COVID-themed phishing and capable of propagating via EternalBlue.
Referenced as a known miner family whose attack techniques may resemble those used to deploy MrbMiner.
Lemon Duck is an advanced cryptocurrency-mining malware that exploits vulnerable Microsoft Exchange Server instances via ProxyLogon, installs miner payloads as a Windows service for persistence, uses certutil and PowerShell for payload delivery, creates user accounts with RDP access, disables security products, and can move laterally by exploiting Oracle WebLogic CVE-2020-14882 on both Windows and Linux.
Advanced cryptomining malware that exploits vulnerable Microsoft Exchange Server instances via ProxyLogon, installs miner payloads as a Windows service for persistence, uses PowerShell and certutil for payload delivery, attempts lateral movement via Oracle WebLogic exploitation, disables security products, creates RDP-enabled user accounts for access retention, and in this campaign also delivers Cobalt Strike beacons.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.