Lemon Duck - Another Look at the Stubborn Cryptominer Malware

Lemon Duck is a cryptomining malware that has been around for a couple of years now. It was first spotted by security researchers in the summer of 2019, just over two years ago, and has since been used in several focused campaigns.

Researchers with Microsoft have released an updated examination of the Lemon Duck cryptominer, outlining some curious trends in its development.

Lemon Duck can creep and take over both Windows and Linux-based networks. However, it has a few features that make it a bit of a special case among other crypto malware.

While most malware simply does its best to avoid detection, Lemon Duck goes above and beyond. It does not simply shut down anti-malware and security software on the compromised systems, it can actually root out other competing malware, even apply vulnerability patches to ensure the system stays clean from other, competing malware.

The trick with patching vulnerabilities doesn't simply ensure an uncontested space for Lemon Duck on the network. It has the additional effect of delaying human investigation, as a company or network might first focus its attention on devices that are still lacking patches.

One example of Lemon Duck mopping up the floor of its own footsteps is an attack using the malware on networks running Microsoft Exchange Server. After abusing bugs to infiltrate the network, Lemon Duck was used to later patch the very bugs that it used to infiltrate in the first place. To top it all off, the threat actors behind this particular campaign used Microsoft's own mitigation tool to patch the bugs.

Additionally, File Duck uses fileless techniques and direct memory and process injections, so detection is further hampered.

All of this combined makes File Duck especially tricky to track down and remove, once it has found its way on a network. When it comes to server platforms that have sufficient resource overhead, the malware's resource drain might not become too noticeable immediately and it can keep running unhampered for extended periods of time.

July 30, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.