Operation Undertow

WAR GAMES · LINUX · difficulty 5 · ~45 min · 22 steps

Your users' video feeds are being steered. You cannot fix what they see. You can destroy the thing that put it there.

Briefing

Welfare wifi, four hundred personal phones, and something is wrong with the feeds. People are seeing short videos that are not in anyone else's feed: content built to unsettle, to make small requests that escalate, to set sections against each other. Two people have acted on it. Morale is going. You are the server admin. Nobody is turning their phone off, and you have no authority over their accounts, their apps or what a platform recommends. So be precise about what you are actually solving. You are not going to filter anybody's feed — you cannot and you must not. You are going to find the thing on YOUR network that is putting content into it, and remove that.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$