A detailed forensic analysis of a nearly two-month intrusion initiated by Lunar Spider via a malicious JavaScript file disguised as a W-9 tax form. The attack chain began with Brute Ratel C4 deployed via MSI, which injected Latrodectus into explorer.exe. Within days, the threat actor discovered plaintext domain admin credentials in an unattend.xml Windows Answer file, enabling rapid privilege escalation. Multiple tools were deployed including Cobalt Strike, BackConnect VNC, a custom .NET backdoor (lsassa.exe), and Zerologon (CVE-2020-1472) exploits for lateral movement. On day 20, data was exfiltrated via Rclone over FTP. Credential harvesting targeted LSASS, browsers, Outlook, and Veeam backup software. Despite extensive access to critical infrastructure including domain controllers and backup servers, no ransomware was deployed before the threat actor was evicted.