Desk live·
ForensicPost
Ransomware/Edge devices/File 23-1010

LockBit Affiliates Used Citrix Bleed to Reach Boeing’s Parts Distribution Unit

CVE-2023-4966 leaked session tokens straight out of NetScaler memory, letting an unauthenticated attacker take over a session without ever holding a password. CISA, the FBI and Boeing published what LockBit 3.0 affiliates did with it.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCitrix NetScaler appliances
ActorLockBit affiliates
D. Kennedy11 min readConfidence: high2 sources reviewed

Citrix published a patch for NetScaler ADC and NetScaler Gateway on 10 October 2023. The flaw, CVE-2023-4966, became known as Citrix Bleed. CISA subsequently issued guidance on active, targeted exploitation, and a joint advisory set out what LockBit 3.0 affiliates were doing with it.

CISA describes a vulnerability that leaks sensitive information from device memory, including session tokens, which an attacker can then use to hijack a session.

The Password Was Never Needed

A session token is what an appliance issues after it has already decided who you are. An attacker holding one arrives after authentication rather than in front of it, which means multi-factor authentication is not bypassed — it is simply not consulted.

This is why resetting passwords was insufficient advice and why the mitigation required terminating existing sessions. Patching stops the leak; it does not invalidate what already leaked. The corpus filed the identical distinction at 25-0723, where a SharePoint chain stole machine keys that kept working after the update, and at 24-0110, where mitigation was explicitly not eviction.

A Victim Contributed To The Advisory

The joint advisory carries technical detail contributed by the FBI, the Australian Cyber Security Centre and Boeing, following LockBit 3.0 affiliate activity against Boeing Distribution Inc., the company’s parts distribution business.

That is unusual enough to note. An affected organisation putting its own incident detail into a public advisory converts a private loss into a defence others can use, and the corpus records very few instances of it — the closest comparisons are the Nevada after-action reports filed at 25-0924 and 25-1107.

Exploitation Outran Disclosure

Reporting described exploitation attempts within hours of public disclosure, using published proof-of-concept code against exposed appliances. The corpus later put this in a single sentence at 25-1216: the patch cycle was designed around a window that no longer exists.

How we reported this

Built on CISA’s guidance page for CVE-2023-4966 and the CISA/FBI/ACSC joint advisory on LockBit 3.0 affiliate exploitation, both retrieved and read by this desk. The Boeing Distribution detail is the advisory’s own, contributed by Boeing. Rapid exploitation following disclosure is from secondary technical reporting and is stated as reported. No victim count is asserted: the advisories do not contain one. No indicators are reproduced here — the advisory carries them and is linked. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Guidance for Addressing Citrix NetScaler ADC and Gateway Vulnerability CVE-2023-4966, Citrix BleedCybersecurity and Infrastructure Security Agency
  2. LockBit 3.0 Ransomware Affiliates Exploit CVE-2023-4966 Citrix Bleed VulnerabilityCybersecurity and Infrastructure Security Agency
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary