LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.

Pull IOCs and campaign context straight into your stack.
13 events from the most recent confirmed update back to the earliest known activity.
SophosLabs published a Trojan-LDMiner.csv indicators-of-compromise file for LemonDuck that listed domains, hashes, webshell paths, mining infrastructure, attacker-created artifacts, and URLs tied to multiple propagation and exploitation vectors. The dataset included 2021 indicators linked to Exchange, WebLogic, EternalBlue, Mimikatz, SSH, Redis, Hadoop, MSSQL, RDP, SmbGhost, and LNK activity, plus historical 2020 LemonDuck indicators.
Cisco Talos reported that LemonDuck updated its infrastructure beginning in April 2021, using fake East Asian ccTLD decoy domains and infection-linked DNS spikes to obscure command-and-control activity. Talos also observed delivery of a Cobalt Strike payload configured as a Windows DNS beacon alongside the botnet's Exchange-targeting and cryptomining operations.
Microsoft observed that in some cases LemonDuck operators used renamed copies of the Microsoft Exchange On-Premises Mitigation Tool to patch the same ProxyLogon vulnerabilities they had exploited. This was done to block competing attackers and reduce defender visibility into the original compromise.
In March and April 2021, LemonDuck used vulnerabilities associated with ProxyLogon to install web shells on outdated Microsoft Exchange Server systems. Operators then used that access to launch additional attacks and deploy automated LemonDuck components.
Sophos stated that Microsoft released critical fixes for Exchange Server in March after the discovery of ProxyLogon. The same source said the exploit was stolen or leaked from researchers within hours of its disclosure to Microsoft.
Microsoft researchers identified a distinct LemonDuck operating structure called "Cat" that emerged in January 2021. The Cat infrastructure was associated with more dangerous post-compromise activity such as backdoor installation, credential theft, data theft, and malware delivery.
In 2020, LemonDuck used COVID-19-themed lures in email attacks. Microsoft also noted that from mid-2020 to March 2021, the campaign's phishing subjects, body content, attachment names, and formats remained largely static.
Microsoft reported that the earliest documented LemonDuck activity dates to cryptocurrency campaigns in May 2019. These early campaigns used PowerShell scripts and scheduled tasks to launch additional scripts.
A technical analysis documented LemonDuck's fileless PowerShell execution, WMI and scheduled-task persistence, credential theft tooling, lateral movement methods, and XMRig mining payloads. The analysis showed the malware functioning as a multi-capability worm-like intrusion toolkit rather than a simple miner.
Microsoft published a second report detailing LemonDuck infection chains, persistence, Defender tampering, lateral movement, and hunting guidance. It highlighted both automated infections beginning with Readme.js and human-operated intrusions via exposed services such as Exchange.
Microsoft published research describing LemonDuck as an evolving cross-platform malware family that had expanded beyond cryptomining into credential theft, lateral movement, email propagation, security control removal, and follow-on payload delivery. The report distinguished the historical "Duck" infrastructure from the newer "Cat" infrastructure used in more dangerous post-compromise activity.
Sophos reported that LemonDuck had incorporated exploitation of Oracle WebLogic Server vulnerability CVE-2020-14882 to download and execute malicious scripts on vulnerable Windows and Linux servers. The report described this as an additional compromise path alongside the campaign's Exchange ProxyLogon activity.
Sophos reported a LemonDuck campaign updated to exploit ProxyLogon against unpatched Exchange servers, using China Chopper web shells, PowerShell and certutil payload delivery, miner installation, and in some variants Cobalt Strike. The report also linked multiple observed variants to the same LemonDuck campaign based on shared tradecraft and credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 146 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcenews.sophos.com
Open sourcedocs.microsoft.com
Open sourcenotes.netbytesec.com
Open sourcetherecord.media
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcegithub.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.