Lemon Duck
- First seen
- 2019-08-01 00:00:00
- Malware type
- cryptominer, worm
- Family
- Malware family
- Last IoC activity
- 2026-07-02 20:39:16
- Profile updated
- 2026-07-07 14:28:47
Context
Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network. The malware runs its payload mainly in memory. Internal network spreading is performed by SMB RCE Vulnerability (CVE-2017-0144), or brute-force attacks.
Exploited vulnerabilities
- CVE-2017-0144 (vulnerability)
Reports & references
- Trend Micro — Proxylogon A Coinminer A Ransomware And A Botnet Join The Part (report)
- news.sophos.com — New Lemon Duck Variants Exploiting Microsoft Exchange Server (report)
- Cisco Talos — Lemon Duck Spreads Wings (report)
- bleepingcomputer.com — Vulnerable Microsoft Sql Servers Targeted With Cobalt Strike (report)
- asec.ahnlab.com — 31811 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lemonduck (report)
- therecord.media — Lemonduck Botnet Evolves To Allow Hands On Keyboard Intrusions (report)
- Microsoft — When Coin Miners Evolve Part 2 Hunting Down Lemonduck And Lemoncat Attacks (report)
- Microsoft — When Coin Miners Evolve Part 1 Exposing Lemonduck And Lemoncat Modern Mining Malware Infrastructure (report)
- CrowdStrike — Lemonduck Botnet Targets Docker For Cryptomining Operations (report)
- news.sophos.com — Lemon Duck Powershell Malware Cryptojacks Enterprise Networks (report)
- cybotsai.com — Lemon Duck Attack (report)
- notes.netbytesec.com — Lemon Duck Cryptominer Technical (report)
- Trend Micro — 000261916 (report)
- bitdefender.com — Bitdefender Pr Whitepaper Lemonduck Creat4826 En En Genericuse (report)