Skip to content

Beapy

Profile source: Mallory opens in a new tab

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 9, 2026
Last activity
Sep 9, 2026
Feed role
C2 / Distribution
Host form
0 IP / 2 hostnames

Leading locations

  • US2

Leading providers

  • Amazon.com, Inc.1
  • The Constant Company, LLC1

Infrastructure traits

  • Hosting 2
  • Proxy 1
  • Vpn 1

Samples

Recent associated samples

Reporting

Research mentioning Beapy

Jan 1
Sophos Threat Research

New Lemon Duck variants exploiting Microsoft Exchange Server | SOPHOS

LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.

Jan 1
Sophos Threat Research

New Lemon Duck variants exploiting Microsoft Exchange Server | SOPHOS

Jun 15
Netbytesec

Lemon-Duck Cryptominer Technical Analysis

Aug 3
The Record Media

LemonDuck botnet evolves to allow hands-on-keyboard intrusions | The Record from Recorded Future News

Jul 29
Microsoft General

When coin miners evolve, Part 2: Hunting down LemonDuck and LemonCat attacks | Microsoft Security Blog

Jul 22
Microsoft General

When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure | Microsoft Security Blog

May 7
Talosintelligence Other

Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs

May 7
Github Web

IoCs/Trojan-LDMiner.csv at master · sophoslabs/IoCs · GitHub

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.