Last seven days
- First activity
- Sep 9, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 2 hostnames
C2 tracking
Derp observations, rolling seven-day window
Samples
21fb40446212b7b239ca06c7f648530d9c531501ad149e1b73f180ca484ee7c3 53336960ab0f7a010b63409fc0707e7e404cd9917b931a6e5bfc8c960ab50707 6686404a5890b58cea217b2be21d39b4e86092d08d354eb7bf5646c12333c92e 904010d7a17230f491f1ca193a4b9b6c00d212f85644a88a84d1fc4f490b3a0d f46c2b2eebc5ea1e44f12d05f26a8ee70cbe1a89dd765edac32a1581f97a2d62 Reporting
LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.