216.73.216.233

LemonDuck Malware Exploiting SMB Vulnerabilities

· Published 09/10/2024 11:13 · Modified 09/10/2024 11:35

Export JSON

Essential information

Published
09/10/2024 11:13
Modified
09/10/2024 11:35
Tags
2024-10-09 CVE-2017-0144 cryptomining eternalblue lemonduck smb
Related entities
1 vulnerabilities (cve), 5 observables, 1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 1 others

Description

malware has evolved into a versatile threat, targeting both Windows and Linux systems. It exploits vulnerabilities, particularly , to gain network access. The malware uses brute-force attacks, creates hidden administrative shares, and executes malicious actions via batch files and PowerShell scripts. It ensures persistence through scheduled tasks, disables Windows Defender, and employs anti-detection mechanisms. The attack includes , system compromise, and lateral movement. disguises itself as legitimate system services, manipulates firewall settings, and uses base64 encoding for obfuscation. It also utilizes Mimikatz for credential theft and employs multiple techniques for stealth and repeated execution.

External references