For two years a malware called Lemon Duck has been infecting computers for mining Monero. In the last two months his activity has increased at an alarming rate.
The researchers of Cisco Talos have been monitoring the Lemon Duck botnet since December 2018. Since August they have seen a large increase in the number of communications with the servers that control the activity of Lemon Duck.
Cisco Talos notes that malware is designed to spread in many ways.
Sometimes new computers are automatically infected using known vulnerabilities such as EternalBlue - which was also used by the famous malware WannaCry.
Like many other malicious groups software that have spread since the start of the Coronavirus pandemic, Lemon Duck is also using phishing emails for COVID-19.
Email messages post officey are very simplistic about the pandemic, (“COVID-19” or “The Truth of COVID-19”) and contain an infected Microsoft Word document.
Mining cryptocurrencies like Monero can be a very intensive process procedure. The harder processors work, the more heat they generate. Without adequate cooling to compensate for the heating, the hardware is at risk.
The criminals behind Lemon Duck want to make sure their operation is profitable. This is why Lemon Duck checks infected machines and shuts them down.