Huntress researchers analyzed several intrusions in September 2023, uncovering a campaign exploiting CVE-2023-3519 in Citrix Netscaler appliances. Attackers used wuauclt.exe process injection, heavily obfuscated PowerShell scripts with Base64/XOR/RC4 encoding, web shells for credential harvesting, and DLL sideloading via legitimate Sysinternals binaries. Initial access vectors included Netscaler exploitation, Citrix-themed phishing using password-protected zip files with LNK objects, and direct social engineering of IT staff. Common tradecraft across victims included LOLBins abuse, BlueVPS-hosted C2 infrastructure, and scheduled task persistence. Indicators of compromise including file hashes, IPs, and domains are provided.

10m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundInitial Intrusion SignsMaking ConnectionsConverging On TradecraftIndicators Of CompromiseShell Commands of Interest