Lemon Duck Cryptocurrency-Mining Botnet Activity Spikes
#1
Information 
Quote:Researchers are warning of a recent dramatic uptick in the activity of the Lemon Duck cryptocurrency-mining botnet, which targets victims’ computer resources to mine the Monero virtual currency.
 
Researchers warn that Lemon Duck is “one of the more complex” mining botnets, with several interesting tricks up its sleeve. While the botnet has been active since at least the end of December 2018, researchers observed an increase in DNS requests connected with its command-and-control (C2) and mining servers since the end of August, in a slew of attacks centered on Asia (including ones targeting Iran, Egypt, Philippines, Vietnam and India).
 
“Cisco Talos has identified activity in our endpoint telemetry associated with Lemon Duck cryptocurrency mining malware, affecting three different companies in the government, retail, and technology sectors,” said researchers with Cisco Talos, in Tuesday research. “We observed the activity spanning from late March 2020 to present.”
 
More recent attacks have included less-documented modules that are loaded by the main PowerShell component – including a Linux branch and a module allowing further spread by sending emails to victims with COVID-19 lures.
 
Threatpost has reached out to researchers for further information about how many victims have been targeted and the extent to which the botnet’s operators have profited off of the cryptomining attacks.

Read more: https://threatpost.com/lemon-duck-crypto...et/160046/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
qBittorrent 5.2.1
qBittorrent 5.2.1:...harlan4096 — 06:59
Bitdefender 27.0.59.334
Bitdefender 27.0.5...harlan4096 — 06:57
Windows 11 New Build Adds Screen Tint, V...
Microsoft has rele...harlan4096 — 06:56
Mozilla Adds Web Serial Support to Firef...
Mozilla has added ...harlan4096 — 06:55
WhatsApp Rolls Out Status Visibility Lis...
WhatsApp is introd...harlan4096 — 06:53

[-]
Birthdays
Today's Birthdays
avatar (40)ihijudu
Upcoming Birthdays
avatar (39)axuben

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>