Netscaler Exploitation to Social Engineering: Mapping Convergence of Adversary Tradecraft Across Victims
ID: d4b8116c-3dde-5f79-ba78-bbdeccd60fcd
STIX ID: report--d4b8116c-3dde-5f79-ba78-bbdeccd60fcd
Feed Name: Huntress Blog
This Huntress report analyzes September 2023 intrusions in which attackers exploited Citrix NetScaler (CVE-2023-3519) and used phishing (password-protected ZIP containing LNK) to sideload malicious DLLs via legitimate binaries (ADExplorer64/resmon/wuauclt), ran heavily obfuscated PowerShell for process injection, established persistence with scheduled tasks and loader DLLs, and deployed web shells and credential harvesters; the document includes IoCs (hashes, IP 91.236.230.111, z9x.org, filenames) and notes activity was identified and remediated prior to known final objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
