OPERATION NIGHTSHADE
OPERATION NIGHTSHADE

Case Number: MP-2026–0415-BC
Subject (Missing Person): Olivia Mia, 24
Suspect Alias: finn oscar max (WhatsApp display name: Mr. finn)
Last Seen: March 28, 2026, 14:30
Location: Local café, Central Business District
Lead Evidence: Encrypted WhatsApp chat log (partial recovery from iCloud backup)

Victim Evidence Arifact
PHASE 1: Coffee Geolocation & Suspect Vehicle Model
Scenari
April 1, 2026 — Metro Police Department Olivia Mia was reported missing by her roommate after failing to return from a coffee date with an unknown male who promised her a luxury handbag. Luckily, she has managed to sent the below image to her friend.
Recovered WhatsApp logs show a 12-day conversation with a contact saved as **Mr. finn (full WhatsApp name: `finn oscar max`**).
Mission
Using open-source intelligence (OSINT), identify:

- The name of the nearby coffee shop where the meeting occurred.
- The make/model of the black car parked opposite the coffee at the time.
Flag Format:CTF{coffee_name_car_model}
PHASE 2: Email Address Lookup via Permutation & Correlation
Scenario
The WhatsApp profile shows the suspect’s profile but no phone number is visible in the chat export. In a voice note, Olivia mentioned: “He said he doesn’t use major social media platforms, but prefers asynchronous communication with friends.”
Mission
Generate email permutations from the suspect’s name, validate which email address is active and have a correlation with the WhatsApp profile and other social media platforms. Analyze any Google Maps location reviews tied to that email for timestamps and coordinates for intelligence collection.
Flag Format: CTF{full_email_address_google_review_timestamp_coordinates}
PHASE 3: Social Media Account Lookup
Scenario
Using the confirmed suspect name, map their digital footprint to discover active social media handles.
Mission
Identify all publicly accessible social media accounts belonging to the suspect.
Flag Format: CTF{social_media_accounts}
(Comma-separated, no spaces – e.g., twitter: @handle, instagram: @handle)
PHASE 4: GitHub Recon — Encoded BSSID & Account Creation Timestamp
Scenario
Olivia’s final messages to a friend suggest the suspect has an active GitHub account where he shares programming work. She suspects he uses an encoded BSSID in one of their repositories to signal meeting locations to accomplices.
Mission
Locate the suspect’s GitHub account, find the encoded BSSID hidden inside a repository, then decode to reveal:
- Wi-Fi key
- WPS PIN
- Timestamp
- Coordinates
- Nearby guesthouse name
- GitHub account creation date
Flag Format: CTF{BSSID_Key_WPS_timestamp_coordinates_guesthouse_name_github_created}
PHASE 5: Accommodation & Dock
Scenario
The suspect is alerted that Olivia may have sent intelligence from a hidden secondary phone. He moves her from the previous hideout to a city hotel near a dock, planning a fast water extraction. Olivia manages to send a photo via iMessage to her friend before being silenced. That photo contains exploitable EXIF metadata.
Olivia’s last photo sent:
[embed]victim_with_gps.jpg Edit descriptiondrive.google.com
Mission
Analyze the iMessage photo’s metadata to determine the current hotel and dock name for real-time law enforcement intervention.
Flag Format: CTF{hotel_name_dock_name}
PHASE 6: Vehicle VIN Decoding & Emergency Geolocation
Scenario
April 2, 2026–03:47 HRS — Metro Police Department, Tactical Response Unit
The suspect, finn oscar max, became aware of Olivia's covert communications after she deliberately instigated a physical confrontation inside their private hotel. The altercation served as a distraction, temporarily halting his planned water extraction via the nearby Dock.
However, the suspect is highly methodical. Within 47 minutes, he forcibly relocated Olivia from the hotel to an unknown secondary location — likely a nearby area with immediate departure capability.
Critical Breakthrough:
During the suspect’s brief absence to purchase food, Olivia accessed her hidden secondary phone and transmitted two pieces of critical intelligence to police:
- A real-time photograph of her surroundings (visible through a vehicle window)
- The suspect’s Vehicle Identification Number (VIN) — visible through the windshield of the car.
She typed via iMessage:
“He left the keys in the ignition when he ran to get food from Burger Haus. I saw the VIN through the glass. 6FPAAAJGSW6T12345. Please find me. The place here looks like a car parking lot — not like the hotel.”
Confirmed Burger Haus Location:
{ 364 Elizabeth St, North Hobart TAS 7000, Australia }
Surveillance Correlation
Dock security cameras near MACq 01 Hotel captured the suspect’s car departing at 03:12 HRS, heading east toward the Brooker Highway.
Traffic cameras along the route confirm the vehicle passed through Prince of Wales Bay (industrial marine hub) at approximately 03:16 HRS before continuing east to Risdon Cove — an isolated industrial docking area suitable for covert vessel loading.
Mission
Using the VIN provided by the victim (6FPAAAJGSW6T12345):
- Decode the VIN to extract vehicle intelligence
- Geolocate the victim’s current locations using:
- Burger Haus location (
364 Elizabeth St, North Hobart) - Victim’s main transport location
(Risdon Rd Service Rd Lutana TAS Australia)
- Provide immediate tactical coordinates of the nearby dock found via the victim’s main transport location.
Flag Format: (VIN_Make_Model_dockname_coordinates)
PHASE 7: Correlation & Final Report
Actionable Intelligence Summary
- Coffee location + vehicle model
- Verified email address + location review data
- Social media accounts
- Last known hideout (from GitHub BSSID decoded)
- Current hotel + dock (from iMessage EXIF)
- Final Victim Transport hideout
Note: Submit a Visual Entity Graph / Link Analysis Diagram illustrating the relationships between all identified intelligence assets.
All reports are required to be submitted via the email address: cybershieldmentor@gmail.com
Final Deliverable Sample:
Feel free to adjust it to match your intelligence findings –
The suspect initially met the victim at the identified café before transporting her in the confirmed vehicle. His verified email address correlates with location review data and active social media accounts. The GitHub BSSID decode revealed a previous hideout, while iMessage EXIF analysis pinpointed the current hotel and adjacent dock. The victim has since been moved to a final transport hideout near an industrial dock. Tactical units are advised to prioritize the final hideout coordinates for immediate intervention, as the suspect has demonstrated rapid relocation capability and planned water extraction.
메타데이터
- post_id
- 4e35ebc405a6
- slug
- operation-nightshade-4e35ebc405a6
- url
- https://medium.com/@preciousvincentct/operation-nightshade-4e35ebc405a6
- canonical_url
- https://medium.com/@preciousvincentct/operation-nightshade-4e35ebc405a6
- author_url
- https://medium.com/@preciousvincentct
- status
- ok
- fetched_at
- 2026-07-21 10:15:56