Your organization has fallen victim to a brutal ransomware attack orchestrated by the notorious Stellar Ransom Syndicate. The encrypted data includes everything—from confidential client files to your cherished memories of a childhood pet. Unfortunately, paying the ransom isn’t an option.
But there's hope.
A post on a dark web forum points to a hidden server believed to hold the decryption keys for Stellar’s victims. Now’s your chance to strike back.
Penetrate the Stellar Syndicate’s infrastructure, locate the recovery key tied to your organization, and reclaim your encrypted data.
This isn’t just about bytes and blocks—it’s personal.
- Target Host:
10.3.32.16
🛑 This is the only authorized target. Everything outside this address is out of bounds.
🛑 If a change is made that makes the challenge impossible to complete, we reserve the right to roll the server back to the last good snapshot. This may cause your progress to be lost and you may have to retrace steps.
- It's in a native windows directory that's hidden from plain view
- ❌ No attacking systems outside the defined scope.
- ❌ No Denial of Service (DoS) or other disruptive tactics.
⚠️ Be mindful of others—especially when running bruteforce tools or resource-intensive scans.- ✅ Play smart. Play fair. Be ethical.
Be the first to:
- Uncover the hidden flag inside the target system.
- Submit the correct flag using the official Microsoft Form.
🖥️ The first successful agent wins: HP 14 Inch Transcend Gaming Laptop & Ruckus Wireless AP + Switch
Use the following as a step-by-step outline or a write-up template:
- Identify live hosts
- Scan for open ports and services
- Document findings
- Investigate each service thoroughly
- Look for versions, directories, config leaks, default creds, etc.
- Exploit vulnerabilities or weak configurations
- Gain shell access or a foothold in the system
- Enumerate the host for local privilege escalation vectors
- Leverage weaknesses to gain root or administrative access
- Search for flag or key files
- Review logs, databases, or backup directories
- Confirm the key/flag is correct
- Submit via the official form
This is your chance to strike back. Get in, retrieve the key, and disappear like a digital ghost.
Stellar won't know what hit 'em.
