
GoldPickaxe: The First iOS Trojan Stealing Your Face
A mobile-first intrusion against a retail bank's managed iPhone fleet. A relationship officer is socially engineered into installing a fake government app through Apple TestFlight and trusting a rogue MDM profile, handing GoldFactory full control of the device. The GoldPickaxe.iOS trojan harvests identity documents and a facial-recognition video, intercepts SMS, and exfiltrates over three split channels: an RSA-encrypted HTTP API, a WebSocket command channel, and an RTMP face-video stream, all to enable AI face-swap fraud against the bank's facial verification. Reconstruct the chain from mobile-threat-defense, MDM, and perimeter firewall telemetry.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Incident brief
0Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.
Find the delivery host
35Everything traces back to one social-engineering link the victim followed. Identify the external host that served the fake app and the rogue device-control profile.
Recover the trojan's file indicator
35Pin down a huntable indicator for the malicious app so the fleet can be swept. Provide the SHA-256 of the installed trojan.
Identify the data-upload command-and-control host
35The operator pulled stolen device, identity, and SMS data to one host over an encrypted web channel. Identify its external IP.
Separate the face-video upload from the command channels
35The captured facial-recognition video left the device on its own dedicated infrastructure. Identify the external IP that received it.
Classify the runtime-code fetch
30Before it could be remotely operated, the trojan reached out for extra operational code. Classify what it did.
Classify the encrypted-upload technique
30The stolen device and identity data was protected on the wire in a specific way. Classify the channel-encryption technique.
7 tasks · 200 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with SIEM concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allMounted and Loaded: ISO Container Delivery of the Bumblebee Loader
An ISO image attachment hides a visible shortcut beside a hidden DLL. The user mounts the container and runs the shortcut, which executes the Bumblebee loader via rundll32 against a DLL export. Bumblebee injects into a signed Windows Mail binary through WMI, beacons HTTPS to a C2 cluster, then layers a Meterpreter stager and a Cobalt Strike beacon. The operator runs AdFind discovery, dumps LSASS with ProcDump, creates a rogue local admin, installs AnyDesk for fallback access, and moves laterally with a harvested domain administrator before the intrusion is contained pre-encryption. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.
Trusted Tool, Hostile Hands: Atera RMM Foothold
A phishing-delivered intrusion that weaponized a legitimate remote-monitoring tool instead of custom malware. A finance analyst was lured by a grant-program email whose link pointed at a file-sharing platform; the download was an MSI that silently installed the Atera agent, registered the endpoint to an attacker-controlled tenant, persisted as a Windows service, and beaconed to Atera's cloud over HTTPS. From the vendor console the operator ran PowerShell discovery and staged a follow-on implant, all over trusted infrastructure. Reconstruct the chain from email, SIEM, and endpoint XDR telemetry and classify the key ATT&CK techniques.
The One-Letter Vendor: Typosquat Invoice Thread Hijack
An accounts-payable team received what looked like a routine reply on an open invoice thread from a trusted supplier. It passed every mail gateway, because the From domain authenticated perfectly. The catch was four mailboxes in the CC field on a domain one letter off the real vendor, quietly hijacking the thread to redirect a six-figure payment to an attacker account. No malware, no account takeover, just mail authentication's blind spot. Work the headers, authentication results, and message traces to reconstruct the vendor-email-compromise fraud.