Lemon Duck

First seen
2019-08-01 00:00:00
Malware type
cryptominer, worm
Family
Malware family
Last IoC activity
2026-07-02 20:39:16
Profile updated
2026-07-07 14:28:47

Context

Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network. The malware runs its payload mainly in memory. Internal network spreading is performed by SMB RCE Vulnerability (CVE-2017-0144), or brute-force attacks.

Exploited vulnerabilities

  • CVE-2017-0144 (vulnerability)

Reports & references

  • Trend Micro — Proxylogon A Coinminer A Ransomware And A Botnet Join The Part (report)
  • news.sophos.com — New Lemon Duck Variants Exploiting Microsoft Exchange Server (report)
  • Cisco Talos — Lemon Duck Spreads Wings (report)
  • bleepingcomputer.com — Vulnerable Microsoft Sql Servers Targeted With Cobalt Strike (report)
  • asec.ahnlab.com — 31811 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lemonduck (report)
  • therecord.media — Lemonduck Botnet Evolves To Allow Hands On Keyboard Intrusions (report)
  • Microsoft — When Coin Miners Evolve Part 2 Hunting Down Lemonduck And Lemoncat Attacks (report)
  • Microsoft — When Coin Miners Evolve Part 1 Exposing Lemonduck And Lemoncat Modern Mining Malware Infrastructure (report)
  • CrowdStrike — Lemonduck Botnet Targets Docker For Cryptomining Operations (report)
  • news.sophos.com — Lemon Duck Powershell Malware Cryptojacks Enterprise Networks (report)
  • cybotsai.com — Lemon Duck Attack (report)
  • notes.netbytesec.com — Lemon Duck Cryptominer Technical (report)
  • Trend Micro — 000261916 (report)
  • bitdefender.com — Bitdefender Pr Whitepaper Lemonduck Creat4826 En En Genericuse (report)

External references