Huntress researchers analyzed several intrusions in September 2023, uncovering a campaign exploiting CVE-2023-3519 in Citrix Netscaler appliances. Attackers used wuauclt.exe process injection, heavily obfuscated PowerShell scripts with Base64/XOR/RC4 encoding, web shells for credential harvesting, and DLL sideloading via legitimate Sysinternals binaries. Initial access vectors included Netscaler exploitation, Citrix-themed phishing using password-protected zip files with LNK objects, and direct social engineering of IT staff. Common tradecraft across victims included LOLBins abuse, BlueVPS-hosted C2 infrastructure, and scheduled task persistence. Indicators of compromise including file hashes, IPs, and domains are provided.