We onboarded a client and did what we always do: put Bitdefender on every machine and read what came back off the first scan.
There was a scheduled task sitting on their domain controller. It had been there since November 2019. Every ten minutes, it ran a PowerShell command that tried to download and execute code from a domain known to be part of the Lemon Duck cryptomining botnet.
Every ten minutes. On the domain controller. Since 2019.
The only reason it wasn’t mining cryptocurrency on their server and spreading across the network was that the attacker’s address had gone offline at some point in the intervening years. They had been saved by the attacker’s infrastructure failing, not by anything anyone on the defending side had done.
Here’s the part that should worry you. The previous IT provider had been managing that environment for years. There was antivirus installed. It was scanning every day. Nobody was reading what it found.
Data nobody looks at isn’t protection. It’s a false sense of one.