LemonDuck
LemonDuck is a threat actor and associated coin-mining malware operation first discovered in 2019. The provided content identifies it as one of at least four threat actors exploiting HTTP File Server (HFS) CVE-2024-23692 to compromise exposed systems and install XMRig Monero miners. In the observed HFS exploitation activity, LemonDuck-associated intrusions also installed XenoRAT and a vulnerability-scanner script. The content states LemonDuck has exploited various vulnerabilities to attack poorly managed systems. The actor is also linked to attacks against poorly managed, internet-exposed Microsoft SQL Server environments. The content describes LemonDuck using scanning and brute-force or dictionary attacks against weak MS-SQL credentials, as well as self-propagation to poorly managed MS-SQL servers. LemonDuck is specifically noted as using xp_cmdshell and CLR Stored Procedures, including re-registering xp_cmdshell if it is unregistered. A LemonDuck-related SqlShell example, evilclr.dll, provides command execution via an ExecCommand() method. Across the described activity, LemonDuck is associated with post-compromise command execution and staging of coin-miner deployment, particularly XMRig/Monero mining. No additional aliases or sub-groups are provided in the content beyond "lemonduck".
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploits the HFS RCE (CVE-2024-23692) to compromise exposed HFS servers, run discovery commands, create/enable hidden local accounts for RDP access, and deploy coin-mining and additional tooling (XMRig, plus XenoRAT and a vulnerability-scanner script).
Uses MS-SQL server brute-force/dictionary attacks (and lateral movement) and then leverages MS-SQL OS command execution features (e.g., xp_cmdshell and CLR Stored Procedures) to download/install additional payloads (e.g., coin miners, other malware).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.