← Back to list

Bank Heist 2–2025 Writeup

Salutations to the curious minds of this generation of CyberSecurity. This season yet again brings an interesting, and not your usual CTF…

cyclescript · 2025-11-24 21:54 · 4 claps · 7.7 min read
#bank-heist #ctf-writeup #ctf-walkthrough #h4k-it #uguntu
Open on Medium ↗
Wiki topics: GEN · Genomics & Sequencing 🔒 · Cybersecurity

Bank Heist 2–2025 Writeup

Salutations to the curious minds of this generation of CyberSecurity. This season yet again brings an interesting, and not your usual CTF, Bank Heist organized by H4k-It. This CTF tested the knowledge and abilities of individuals by relying not on any hacking or automated tools, but pushing their brain to that point of not over thinking but delivering the necessary results. Okat enough of the talking, let’s hop into it.

Bank Heist 2 details: The Bank Heist 2 brings back the high-stakes world of intelligence, deception, and digital warfare where strategy matters more than speed, and every move leaves a trace. Mr. X and the crew are back with another mission. Whispers of insider manipulation, backdoor exploits, and social engineering ripple through the city’s underworld.

The Bank Heist 2 comprised of 7 intriguing challenges that was in form of checkpoints, each solved checkpoint leading and giving a hint unto the next. Link to the challenge: **bank heist 2 — 2025**

Challenges from the Bank Heist.

Challenges from the Bank Heist.

Check Point 1 — The Art of Invisibility

Check point 1 provides us with a document that says that can act as guide to answer the challenges. From the document, we find very valuable information for the challenges.

Useful information discovered:

domain of the bank | Project ‘Trust Fund’

domain of the bank | Project ‘Trust Fund’

Bank accounts

Bank accounts

  1. http://lindensennational.com
  2. Trust Fund
  3. Two Bank accounts: Prime minister’s & Offshore account

From the information discovered, our goal is to gain access to the systems of the bank which is highly secured, transfer money from the prime minister’s account, send it to the offshore account and disappear like we were never there. Sneaky right?

But wait, we haven’t gotten our first flag yet, from the title of our challenge, ‘the art of invisibility’, I noticed a very not so normal awkward space between the last paragraph and note of the document.

Very awkward right?

Very awkward right?

After selecting all text and changing it to black font, lo and behold we have our first flag.

Sometimes, what you’re looking for is just right infront of you!

Sometimes, what you’re looking for is just right infront of you!

Check Point 2— Social creatures

Check point 2 inquires of us what is the name of our target. Since this challenge is under OSINT, it’s was time to get out OSINT game on.

And since we are trying to hit the bank, that means our culprit has to be an employee of the bank. Number one place to run to was the website of the bank. Which we found earlier in the provided document: **http://lindensennational.com**

A summary of what was found on the bank domain:

  1. The team of the bank from, CEO, CTIO, and so on including a manager 2.A blog 3.News of the launch of the “Royal Trust Fund” 4.A subdomain with a login page

After taking some good minutes crawling through the website, we find an interesting article by the bank manager, Amelia Anderson, talks about her position as the overseer of the Royal Trust Fund, and this is our main target to hit.

This means we found our way into what we are after, making Amelia Anderson our target. And yes you got that correctly, we have our second flag: GoH{Amelia, Anderson}

Now we can move on to the next checkpoint/ challenge.

Check Point 3— Bullseye

Now our next challenge asks us of what method can be used to build a clear, structured and understanding of who or what we ought to attack before touching any tool. I know what you’re thinking, I did too as well, we all did and the term “Reconnaissance”, crossed our minds, but wait, they said before touching any tool, the leaves us with passive reconnaissance which deals with OSINT, and other means that do not involve interacting with the the target system or person. If you have tried all these, congratulations you have failed.

My exact frustration

My exact frustration

But after making some good research, I found a term called, profiling

Profiling:is the process of gathering and analyzing extensive information about a target organization, its systems, and its people to build a detailed understanding of potential attack vectors and simulate a realistic cyberattack.

This perfectly fits in our challenge, and hence we have successfully found our third flag and the hint to our next checkpoint flag: GoH{profiling}

A very interesting CTF right? Okay now let’s come back to the game, the Trust Fund won’t hack itself

Time to build a profile on our manager, Amelia Anderson

After reading through her employee profile, and blogs, these are the finding about Amelia Anderson:

Amelie Anderson’s email and linkedin profile:

Email: amelia.n.andersons@gmail.com

We find out that she loves exploring AI tools and automatino agents, and other activities lije baking, gardening and picking up her guitar, hopefully she plays that well.

Now that we have gathered some very good and useful information, we can proceed to the next challenge.

Check Point 4—When everything fails

Challenge 4 asks us what attack vector do we ought to use, since we have a rich profile of our culprit, Amelia Anderson, including her email. The best point of our attack is phishing. which gives us our fourth flag. Flag: GoH{phishing}

Check Point 5— Let me in

Now we have been asked of the culprit, Amelia Anderson’s, username and password. Remeber when we talked about findings from the bank domain/website, we discovered a login page for the banking system: http://internetbanking.lindensennational.com/

So we need to phish this culprit target of ours and get her credentials.

I created a phishing page by cloning the exact login page of the internet banking system using social engineering toolkit. Then crafted an email posing to be from IT support and guess what, she apparently attended an awareness training at such a crucial time as this:

But after that, I tried a different angle talking about how great it is of her to embrace AI and how great of a solution that we have to integrate with the banking system which will bring about efficiency and simplification of tasks.

And there we have her attention, from here on we share with her a test simulation of the “AI and banking system” which is actually our phishing page, and from this she actually enters her actual banking credentials that we are able to intercept.

And from this information we have our 5th flag: GoH{amelia.andersons.lnb.com, QseNM5npM@bV3C%pg5}

Check Point 6 — The Travellor

Now from the obtained credentials, we can log into the online banking system

From the title of the challenge, talking about travelling or in this instance browsing, we navigate through the different sections and webpages of the online banking system, under the section of loans is where we find our 6th flag:

We’re almost there

We’re almost there

Flag: GoH{You_Have_From_A-Far}

Check Point 7— The bank transfer

Finally lads, we have made it, from the OSINT to the final show down of making that juicy transfer, but how do we do that. After examining the source code of the banking system, we discover exposed api files, calling us to explore them.

After reading through the code of the js files, we now understand how the transfer is working from the transfer.js

Note: during the challenge i took no screenshots of this and at the moment, the banking system that used for the CTF is down.

But from there, we fire up burpsuite and intercept one of the transfer, we replace the existing accounts in the intercept, the source account with the prime minister’s account and the destination account with the off shore account, plus the amount of money to be sent.

I mean it’s a greedy prime minister, he probably got a net worth, knock yourself out with what ever amount. Don’t be shy.

After a successful transfer, we receive a message from the messsenger of Mr.X which has our last flag.

Flag: GoH{Welcome_To_The_Club_Operative4}

And this comes to a conclusion of the Bank hesit 2 — 2025. This CTF greatly tested our thinking and knowledge in Cyber Security and one of my key takeaways from this is that Hacking isn’t all about knowing what tools to run and what automation to put in place to scan for a vulnerability. It all comes back to the understanding of your target and swaying one without having the need to fireup any hacking tool.

This challenge tested the skills of social engineering, OSINT, and information gathering of a target. Mr. X will be so proud of you. Until we meet in the next. Keep being a great cyberninja and keep your cyberspace safe and secure.


메타데이터
post_id
ca16eb3acb52
slug
bank-heist-2-2025-writeup-ca16eb3acb52
url
https://medium.com/@cyclescript/bank-heist-2-2025-writeup-ca16eb3acb52
canonical_url
https://medium.com/@cyclescript/bank-heist-2-2025-writeup-ca16eb3acb52
author_url
https://medium.com/@cyclescript
status
ok
fetched_at
2026-07-15 04:57:40