Skip to main content
DPRK Fake IT Worker: Insider Access and Exfiltration operation cover
AdvancedSIEMCloudXDRPRO

DPRK Fake IT Worker: Insider Access and Exfiltration

A fraudulent remote software engineer embedded under a stolen identity gains network access on their first day and immediately begins collecting source code, architecture documentation and cloud secrets. The session originates entirely from a single hosting-range ASN, persists through AnyDesk and ngrok tunnels, and ends with a dual-channel exfiltration via Rclone and AzCopy. Reconstruct the full chain from Azure AD audit events, VPN and endpoint telemetry.

1h 25m
9 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Map the access origin

20

Every alert from this session points to an unusual source. Before tracing the operative's actions, establish where all the malicious connections originate at the network level.

Hint available
2

Name the identity pivot

20

Once inside Azure AD, the operative did not stop there. The cloud audit log shows access to source-code and documentation platforms that were not directly authenticated -- they inherited trust from the initial login.

Hint available
3

Track the remote-access implant

25

The operative did not rely solely on the VPN for continued access. The endpoint telemetry on the jump server shows a remote-access tool was installed silently from the SSH session -- giving the operator a channel that does not depend on the VPN tunnel staying open.

Hint available
4

Find the exfiltration endpoint

25

The operative staged repository archives locally and then transferred them off the network. Pinpoint the external address that received the bulk transfer.

Hint available
5

Identify the cloud staging account

25

In parallel with the endpoint-based exfil, the operative used a cloud transfer tool to upload a compressed source archive to an Azure storage account that does not belong to any known project. Identify that storage account name.

Hint available
6

Hash the exfil binary

30

One of the three unsigned binaries dropped to ProgramData was the tool responsible for the bulk exfiltration. Retrieve its SHA-256 hash from the endpoint telemetry.

Hint available
7

Correlate the impossible travel

30

One cloud alert flagged an impossible-travel event for the operative's account. Two sessions for the same account were authenticated from geographically inconsistent IPs within a window too short for legitimate travel. Identify the anomalous IP that triggered that alert.

Hint available
8

Expose the persistence tunnel

30

Beyond AnyDesk, the operative ran a second tunnel that routes incoming connections through an external cloud relay service. This tunnel survives VPN disconnection and lets the operator re-enter the network without re-authenticating to any corporate service. Identify the domain the tunnel connects to.

Hint available
9

Reconstruct the exfil path

35

The operator configured Rclone to transfer data to a named remote and a specific path on that remote. Both are visible in the command-line arguments in the process telemetry. Reproduce the full rclone destination argument exactly.

Hint available

9 tasks · 240 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
Cloud log analysis
XDR log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with Cloud concepts
  • Familiarity with XDR concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts