Read the 2026 State of Identity Security Report

[GET REPORT]
Close Icon
Linkedin
Linkedin
Illustration Cloud

Permiso weighs in on CrowdStrike's LemonDuck malware finding

On April 22, Permiso provided their perspective of CrowdStrike’s recent publication on LemonDuck malware shifting targeting to container and cloud technologies in the CSO Online article “Cryptomining botnet targeting Docker on Linux systems”. While crypto mining malware is not typically perceived as a highly sophisticated operation, this does provide a public example of attackers shifting tactics to take advantage of cloud resources, and general lack of detection tooling and expertise in the cloud.

With this version of LemonDuck malware, the initial infection was focused on the Docker API. One of the more interesting facets of this iteration of LemonDuck beyond the Docker targeting is that it specifically disabled Alibaba’s cloud monitoring service endpoint. Learn more about the campaign and see experts weigh in:

Illustration Cloud

Related Articles

Permiso Research Finds Up to 75% of Security Incidents Are Identity-Related, Highlighting New AI-Driven Risk

Survey of 500+ Security & Identity Professionals Shows Dramatic 47-Point Drop in Visibility Confidence as 91% Expect Explosive Growth in AI-Generated Identities in 2026

Permiso Builds Leadership Team for Next Stage of Growth as Demand Builds for Identity Security Protection

Permiso Security, the leading identity security company protecting human, non-human, and AI identities across hybrid and multicloud environments, today announced several strategic hires and executive promotions as Permiso scales in response to

View more posts