On this page
New variants of the Lemon Duck cryptominer have been observed actively exploiting vulnerabilities in Microsoft Exchange Server to compromise servers and spread across networks.
What is Lemon Duck?
Lemon Duck is a self-propagating cryptocurrency mining malware family. Once it infects a machine, it uses a range of propagation techniques, including weak credentials, unpatched vulnerabilities and PowerShell abuse, to move laterally through the network and install a cryptocurrency miner that silently consumes CPU resources.
Exploiting Microsoft Exchange Server
Recent variants have been seen exploiting known Microsoft Exchange Server vulnerabilities as an initial infection vector. Once a server is compromised, the malware drops its components, disables security tools where possible, and attempts to spread to other machines on the network.
How to protect your organisation
- Apply Microsoft's security patches for Exchange Server immediately, including cumulative updates and the out-of-band fixes for known exploited vulnerabilities.
- Restrict and monitor remote PowerShell and management interfaces that Exchange requires.
- Enable multi-factor authentication for all administrative accounts.
- Segment your network so that a single compromised server cannot reach the entire environment.
- Monitor for anomalous CPU usage and unexpected outbound connections, common signs of mining activity.
If you suspect an Exchange Server has been compromised, isolate it from the network before carrying out forensic review and remediation. For expert assistance securing and hardening your Microsoft environment, contact the Intellinks East Africa team.
Written by
Intellinks East Africa
Technical insights from the Intellinks East Africa team on IT security, backup, cloud and operations.
Share this article