Skip to main content
GoldPickaxe: The First iOS Trojan Stealing Your Face operation cover
IntermediateSIEMFirewall

GoldPickaxe: The First iOS Trojan Stealing Your Face

A mobile-first intrusion against a retail bank's managed iPhone fleet. A relationship officer is socially engineered into installing a fake government app through Apple TestFlight and trusting a rogue MDM profile, handing GoldFactory full control of the device. The GoldPickaxe.iOS trojan harvests identity documents and a facial-recognition video, intercepts SMS, and exfiltrates over three split channels: an RSA-encrypted HTTP API, a WebSocket command channel, and an RTMP face-video stream, all to enable AI face-swap fraud against the bank's facial verification. Reconstruct the chain from mobile-threat-defense, MDM, and perimeter firewall telemetry.

45m
7 tasks
50 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Incident brief

0

Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.

2

Find the delivery host

35

Everything traces back to one social-engineering link the victim followed. Identify the external host that served the fake app and the rogue device-control profile.

SOC{domain}Hint available
3

Recover the trojan's file indicator

35

Pin down a huntable indicator for the malicious app so the fleet can be swept. Provide the SHA-256 of the installed trojan.

SOC{sha256}Hint available
4

Identify the data-upload command-and-control host

35

The operator pulled stolen device, identity, and SMS data to one host over an encrypted web channel. Identify its external IP.

SOC{a.b.c.d}Hint available
5

Separate the face-video upload from the command channels

35

The captured facial-recognition video left the device on its own dedicated infrastructure. Identify the external IP that received it.

SOC{a.b.c.d}Hint available
6

Classify the runtime-code fetch

30

Before it could be remotely operated, the trojan reached out for extra operational code. Classify what it did.

SOC{Txxxx}Hint available
7

Classify the encrypted-upload technique

30

The stolen device and identity data was protected on the wire in a specific way. Classify the channel-encryption technique.

SOC{Txxxx.xxx}Hint available

7 tasks · 200 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with SIEM concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
IntermediateXDRSIEM

Mounted and Loaded: ISO Container Delivery of the Bumblebee Loader

An ISO image attachment hides a visible shortcut beside a hidden DLL. The user mounts the container and runs the shortcut, which executes the Bumblebee loader via rundll32 against a DLL export. Bumblebee injects into a signed Windows Mail binary through WMI, beacons HTTPS to a C2 cluster, then layers a Meterpreter stager and a Cobalt Strike beacon. The operator runs AdFind discovery, dumps LSASS with ProcDump, creates a rogue local admin, installs AnyDesk for fallback access, and moves laterally with a harvested domain administrator before the intrusion is contained pre-encryption. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h50 pts
IntermediateXDRSIEM

Trusted Tool, Hostile Hands: Atera RMM Foothold

A phishing-delivered intrusion that weaponized a legitimate remote-monitoring tool instead of custom malware. A finance analyst was lured by a grant-program email whose link pointed at a file-sharing platform; the download was an MSI that silently installed the Atera agent, registered the endpoint to an attacker-controlled tenant, persisted as a Windows service, and beaconed to Atera's cloud over HTTPS. From the vendor console the operator ran PowerShell discovery and staged a follow-on implant, all over trusted infrastructure. Reconstruct the chain from email, SIEM, and endpoint XDR telemetry and classify the key ATT&CK techniques.

55m50 pts
IntermediateEmailSIEM

The One-Letter Vendor: Typosquat Invoice Thread Hijack

An accounts-payable team received what looked like a routine reply on an open invoice thread from a trusted supplier. It passed every mail gateway, because the From domain authenticated perfectly. The catch was four mailboxes in the CC field on a domain one letter off the real vendor, quietly hijacking the thread to redirect a six-figure payment to an attacker account. No malware, no account takeover, just mail authentication's blind spot. Work the headers, authentication results, and message traces to reconstruct the vendor-email-compromise fraud.

40m50 pts