Skip to main content
FluBot: The Parcel-Delivery Text That Spreads Itself operation cover
COMING SOONBeginner

FluBot: The Parcel-Delivery Text That Spreads Itself

A managed Android handset at Larkfield Mutual is infected by FluBot after the employee taps a smishing SMS impersonating a DHL parcel-delivery notice. The fake tracking page serves a parcel-themed APK, and once Accessibility and SMS permissions are granted, the trojan steals the contact list, blasts the same lure to every contact, intercepts bank 2FA codes, and tunnels its command-and-control over DNS-over-HTTPS. Walk the mobile telemetry and firewall logs step by step to trace the lure, the sideload, the contact theft, the SMS worm, and the hidden C2.

25m
6 tasks
25 points
Free

Launches tomorrow

Jul 3, 2026

Friday, July 3, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops — free forever.

Training Tools

SIEMFirewall

What you'll investigate

6 objectives unlock when this operation goes live.

1Brief: a parcel text that texts itself
2Find the link the victim tapped
3Name the app that was sideloaded
4Spot where the stolen contacts went
5Measure how far it tried to spread
6Label how the C2 stayed hidden

Be first when it launches

Create your free account now. The moment this operation goes live on Jul 3, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free

No credit card required — free forever