{
  "id": "case-boeing-lockbit",
  "slug": "boeing-lockbit-citrixbleed-ransomware",
  "title": "Boeing Commercial Airplanes Parts Supply Extortion",
  "summary": "LockBit ransomware affiliates exploited the Citrix Bleed zero-day (CVE-2023-4966) to bypass multi-factor authentication, exfiltrating 43 gigabytes of sensitive internal aerospace data and parts distribution documentation from Boeing parts and distribution business.",
  "case_number": "SEC Form 8-K Disclosure",
  "court": "U.S. District Court for the Eastern District of Virginia",
  "district": "E.D. Va.",
  "country": "United States",
  "opened_at": "2023-11-02",
  "status": "alleged",
  "victim_sector": "Aerospace, Defense & Manufacturing",
  "victim_country": "United States",
  "loss_amount_usd": 60000000,
  "loss_amount_note": "Distribution disruption, internal remediation, and third-party supplier forensic audits.",
  "first_seen_at": "2023-10-25T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "lockbit",
  "defendant_slugs": [],
  "cves": [
    "CVE-2023-4966"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Ransomware affiliates leveraged Citrix Bleed (CVE-2023-4966) to extract active user session tokens from NetScaler appliance memory, hijacking authenticated sessions without entering MFA codes.",
      "evidence_locator": "CISA Advisory AA23-325A: LockBit 3.0 Ransomware Affiliates Exploit CVE-2023-4966",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-325A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1539",
      "evidence_excerpt": "Stolen session cookies were injected directly into HTTP request headers to access internal Boeing parts portal web applications.",
      "evidence_locator": "FBI Flash Report on Citrix Bleed Exploitation",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FBI Flash Alert",
      "source_url": "https://www.cisa.gov"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Threat actors transferred approximately 43GB of backup archives, financial spreadsheets, and engineering vendor lists to LockBit extortion infrastructure.",
      "evidence_locator": "DOJ Indictment: U.S. v. Khoroshev",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Khoroshev Indictment",
      "source_url": "https://www.justice.gov",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-10-25",
      "description": "LockBit affiliates compromise Boeing parts and distribution portal via unpatched Citrix gateway."
    },
    {
      "event_type": "disclosure",
      "event_date": "2023-11-02",
      "description": "Boeing confirms cyber incident impacting its parts business."
    },
    {
      "event_type": "extortion",
      "event_date": "2023-11-10",
      "description": "LockBit syndicate publishes 43GB of stolen data after Boeing refuses extortion payment."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Exploitation of the CitrixBleed vulnerability (CVE-2023-4966) on an internet-facing Citrix NetScaler ADC gateway, enabling unauthenticated remote attackers to dump memory and hijack valid enterprise user sessions.",
    "blast_radius": "LockBit ransomware group exfiltrated approximately 43 gigabytes of internal parts distribution, aerospace supplier, and technical documents, publishing the entire archive on their Tor leak site after Boeing refused to pay the extortion demand.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "CitrixBleed Session Hijack Ingress (CVE-2023-4966)",
        "description": "Attackers exploited CVE-2023-4966 buffer overflow on NetScaler gateways to extract session cookies from memory, bypassing multifactor authentication.",
        "technical_artifacts": [
          "CVE-2023-4966 exploit",
          "Hijacked NetScaler session cookie"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Discovery",
        "title": "Host Reconnaissance & Network Discovery",
        "description": "Threat actors used PowerShell and standard Windows utilities to map internal networks and identify file servers supporting commercial parts distribution.",
        "technical_artifacts": [
          "PowerShell discovery scripts",
          "Network share enumeration"
        ],
        "mitre_technique_id": "T1087"
      },
      {
        "phase": "Collection",
        "title": "Sensitive Document Harvesting",
        "description": "Operatives collected internal engineering documents, supplier invoices, and parts distribution logs into compressed staging folders.",
        "technical_artifacts": [
          "Aggregated technical PDFs",
          "Supplier invoice databases"
        ],
        "mitre_technique_id": "T1005"
      },
      {
        "phase": "Exfiltration",
        "title": "Cloud Storage Exfiltration via Rclone",
        "description": "Using command-line cloud transfer tools (Rclone), the attackers exfiltrated the 43 GB data repository to external cloud storage providers.",
        "technical_artifacts": [
          "Rclone configuration",
          "Cloud storage outbound streams"
        ],
        "mitre_technique_id": "T1567.002"
      },
      {
        "phase": "Extortion Impact",
        "title": "Extortion Shaming & Public Leak",
        "description": "Following non-payment of extortion demands, LockBit released the exfiltrated archives on their dark web leak portal.",
        "technical_artifacts": [
          "LockBit Tor leak publication",
          "Extortion ransom communication"
        ],
        "mitre_technique_id": "T1651"
      }
    ],
    "defensive_takeaways": [
      "Rapidly apply vendor security updates for public-facing edge appliances and terminate all active sessions post-patching.",
      "Implement behavioral anomaly detection on edge VPN and ADC gateways to detect session cookie reuse from novel IP addresses.",
      "Block unauthorized egress connections to public cloud storage and file-sharing infrastructure.",
      "Maintain strict access control lists on commercial parts distribution and supplier document repositories."
    ]
  }
}