LemonDuck-competition-killer


Description

LemonDuck is an actively updated and robust malware primarily known for its botnet and cryptocurrency mining objectives. First discovered in 2019, LemonDuck has since adopted more sophisticated behavior and escalated its operations in 2021. Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.

Query · kql

DeviceProcessEvents
| where ProcessCommandLine has_all("schtasks.exe","/Delete","/TN","/F")
| summarize make_set(ProcessCommandLine) by DeviceId
| extend DeleteVolume = array_length(set_ProcessCommandLine)
| where set_ProcessCommandLine has_any("Mysa","Sorry","Oracle Java Update","ok")
| where DeleteVolume >= 40 and DeleteVolume <= 80
Raw source LemonDuck-competition-killer · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 9f6b9f77-0183-4d5b-89a3-761d308cbfad
name: LemonDuck-competition-killer
description: |
  LemonDuck is an actively updated and robust malware primarily known for its botnet and cryptocurrency mining objectives. First discovered in 2019, LemonDuck has since adopted more sophisticated behavior and escalated its operations in 2021. Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceProcessEvents
tactics:
- Execution
- Persistence
- Defense evasion
- Impact
- Malware, component
query: |
  DeviceProcessEvents
  | where ProcessCommandLine has_all("schtasks.exe","/Delete","/TN","/F")
  | summarize make_set(ProcessCommandLine) by DeviceId
  | extend DeleteVolume = array_length(set_ProcessCommandLine)
  | where set_ProcessCommandLine has_any("Mysa","Sorry","Oracle Java Update","ok")
  | where DeleteVolume >= 40 and DeleteVolume <= 80

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.