
The Lemon_Duck cryptomining malware has been upgraded to be able to compromise Linux systems (via SSH brute force attacks), exploit systems vulnerable to the SMBGhost vulnerability , and infect servers running Redis and Hadoop.
The Lemon_Duck cryptomining malware, detected last year by Trend Micro and further examined by SentinelOne, typically targets corporate networks, gaining access to the MS SQL via brute-force or the SMB protocol using the EternalBlue exploit.
Once it successfully infects a device, the malware installs an XMRig Monero (XMR) CPU miner payload that uses the compromised system's resources to mine cryptocurrency for Lemon_Duck's operators.
Lemon_Duck cryptomining malware looks for Linux systems and cloud applications
To find Linux devices that it can infect via SSH brute force attacks, Lemon_Duck uses a port scanner, which searches for Linux systems connected to the Internet, with the exposed TCP port 22 used for SSH Remote Login.
“When it finds them, it launches an SSH brute force attack on those machines, with the username root and a list of passwords,” said security Rajesh Nataraj. “If the attack is successful, the attackers download and execute malicious code.”
To ensure that the malware survives between system reboots, a cron job is added.
The Lemon_Duck cryptomining malware then searches for more devices to install payloads on, Linux collecting SSH credentials from the /.ssh/known_hosts file
Lemon_Duck also has the ability to neutralize other cryptominers that may be installed on Linux systems, to ensure that only its operators can steal cryptocurrencies.

Lemon_Duck cryptomining malware upgraded for new attacks
The cryptojacker is also being distributed via large-scale COVID-19-themed spam campaigns. The malware uses an RTF exploit that targets the Microsoft Office remote code execution (RCE) CVE-2017-8570to deliver the malicious payload.
Recently, Lemon_Duck operators added a feature that exploits the Windows SMBGhost vulnerability (CVE-2020-0796) .
However, instead of exploiting this vulnerability to execute malicious code, malware operators use it to collect information about compromised computers.
For about two months, between June and August, the hackers behind the Lemon Duck cryptomining malware disabled the EternalBlue and Mimikatz features, likely to see the effectiveness of SMBGhost.
After deploying the XMRig miner on compromised devices, the malware will attempt to disable SMBv3 and block SMB ports 445 and 135 to prevent others from exploiting the infected, vulnerable systems.
Additionally, the operators of the Lemon_Duck cryptomining malware have added support for scanning and compromising servers with exposed Redis (REmote DIctionary Server) databases and Hadoop clusters, which are managed using YARN (Yet Another Resource Negotiator).
“The Lemon_Duck cryptomining malware is one of the most advanced types of cryptojacker payloads,” explained Sophos security researcher Rajesh Nataraj.
“Its creators are constantly updating the code with new techniques to avoid detection, and the miner itself is fileless, meaning it leaves no traces on the victim's file system.”
