logo

Netscaler Exploitation to Social Engineering: Mapping Convergence of Adversary Tradecraft Across Victims

ID: d4b8116c-3dde-5f79-ba78-bbdeccd60fcd

STIX ID: report--d4b8116c-3dde-5f79-ba78-bbdeccd60fcd

Feed Name: Huntress Blog

Threat Score
72/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

This Huntress report analyzes September 2023 intrusions in which attackers exploited Citrix NetScaler (CVE-2023-3519) and used phishing (password-protected ZIP containing LNK) to sideload malicious DLLs via legitimate binaries (ADExplorer64/resmon/wuauclt), ran heavily obfuscated PowerShell for process injection, established persistence with scheduled tasks and loader DLLs, and deployed web shells and credential harvesters; the document includes IoCs (hashes, IP 91.236.230.111, z9x.org, filenames) and notes activity was identified and remediated prior to known final objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.