Operation Dead Reckoning

AI · LINUX · difficulty 2 · ~10 min · 12 steps

Machine-generated credential stuffing from 9,000 addresses. Blocking by hand loses.

Briefing

Your login endpoint is taking 40,000 attempts a minute. The credentials are real — bought from a breach and replayed — and the sources are a residential proxy pool: thousands of addresses, each used a handful of times, rotating constantly. Sessions are being taken right now. Every instinct that works on a human attacker fails here. You cannot ban 9,000 addresses, and by the time you have banned a hundred they are on a different hundred. Write ONE rule that answers all of them, then take the advantage away entirely.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$