Skip to main content
RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining operation cover
IntermediateFirewallSIEMXDRPRO

RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining

A Mirai-derived DDoS botnet brute-forces SSH on an internet-exposed Linux edge gateway, persists an attacker SSH key in root's authorized_keys, pulls a Bash stager, and drops a single merged binary that fuses the RapperBot DDoS client with an embedded XMRig Monero miner. The bot registers with a hardcoded C2 over a custom binary protocol, floods an external victim with UDP/TCP/HTTP traffic, and quietly mines Monero through two proxy pools hosted on the C2 IP itself. Reconstruct the chain from SIEM, endpoint XDR, and perimeter firewall telemetry.

1h
7 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Incident brief

0

Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.

2

Pin down the brute-force foothold

35

Everything starts with one account falling to password guessing on the exposed gateway. Identify the external source that guessed it.

Hint available
3

Find the persistence the attacker left behind

35

Before doing anything loud, the operator made sure they could get back in even after a reboot. Identify the file they modified to do it.

Hint available
4

Recover the dropped payload's hash

40

A stager pulled the real malware down and ran it from a temporary directory. Provide the SHA-256 of the binary it dropped.

Hint available
5

Separate the flood from the rest of the traffic

35

Once running, the bot turned the gateway into a weapon against someone else. Identify the external address it flooded.

Hint available
6

Expose where the mining traffic really went

40

The miner deliberately blurred the line between control and mining infrastructure. Identify the IP the mining proxies were hosted on.

Hint available
7

Classify the dual impact technique

30

Name what the miner did to the host, in ATT&CK terms. Classify the impact technique behind the hidden mining.

Hint available

7 tasks · 215 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
Firewall log analysis
SIEM log analysis
XDR log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with Firewall concepts
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts

Ready to investigate?

More Operations

View all
IntermediateXDRSIEM

RedTiger Stealer: GoFile + Discord-Webhook Exfiltration

A single-host smash-and-grab infostealer intrusion. An artist ran a PyInstaller-compiled executable disguised as a Roblox FPS-unlocker mod that was actually the open-source RedTiger stealer. In one short burst it unpacked to Temp, blackholed security-vendor domains in the hosts file, persisted via the Startup folder, injected JavaScript into the Discord client, and archived Discord tokens, browser credentials and cards, a crypto wallet, a webcam frame, and a screenshot. Exfiltration ran in two stages over legitimate cloud: the loot ZIP was uploaded to GoFile, then the download link plus victim recon was posted to a Discord webhook. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

55m50 pts
IntermediateSIEMFirewall

Hidden in the Pixels: LSB Steganography Exfil From an Infected Endpoint

A LummaC2/Vidar-style infostealer smash-and-grab. A finance analyst was tricked by a fake CAPTCHA (ClickFix) into pasting an mshta command into the Run box, which staged hidden PowerShell, downloaded the Lumma stealer, and harvested browser credentials, cookies, and wallet artifacts. To smuggle the loot out, the operator LSB-encoded the stolen blob into an oversized PNG and uploaded it to a public image host, off the command-and-control channel. Reconstruct the chain from SIEM and perimeter firewall telemetry and classify the key ATT&CK techniques.

30m50 pts
IntermediateXDRFirewall

Docker Hub Supply Chain: A Public Image on a Shared Build Runner

A platform engineer pulls a public Docker Hub image advertised as a network scanning utility onto a shared Linux build-runner. Hours later the host is still pinned at full CPU with its build queue drained, nothing deployed and no data alarms raised. Reconstruct what the image actually did on the host from endpoint XDR and perimeter firewall telemetry, and classify the key ATT&CK techniques.

40m50 pts