Operation Cold Key

LOCKOUT · WINDOWS · difficulty 5 · ~45 min · 20 steps

No malware. A Group Policy Object turned on BitLocker across the estate with somebody else's recovery key.

Briefing

05:50. Four hundred and eleven workstations are sitting at a blue screen asking for a BitLocker recovery key. Nobody deployed anything. There is no encryptor to find, no ransom note on disk, and your endpoint agent has not raised a single alert — because nothing malicious ever ran. A Group Policy Object was modified at 22:40 last night. It enables full-volume encryption, supplies a recovery password the attacker generated, and turns off escrow to Active Directory. Every machine that has rebooted since is theirs. The rest are still running and still encrypting. That is your window.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$