A detailed incident report covering a two-stage intrusion that began with exploitation of CVE-2023-46604 on an exposed Apache ActiveMQ server. The threat actor used a malicious Java Spring XML configuration to achieve RCE, deployed a Metasploit stager, escalated to SYSTEM, dumped LSASS credentials, and moved laterally across the network. After being evicted, they returned 18 days later using the same unpatched vulnerability, leveraged previously stolen credentials, installed AnyDesk for persistence, and deployed LockBit ransomware via RDP across multiple hosts. The ransomware binary was built using the leaked LockBit Black builder with a modified ransom note directing victims to the Session messaging app, suggesting an independent threat actor. Total time from initial access to ransomware deployment was approximately 419 hours, but the second-stage window was under 90 minutes. Full MITRE ATT&CK mapping, IOCs, Sigma rules, YARA signatures, and network detection rules are provided.