H4K-it2025 the Bankheist2 writeu
http://lindensennational.com/ => this is my target.. this is the platform to hack… the information we have is that it is a Trust Fund as…
H4K-it2025 the Bankheist2 writeup
http://lindensennational.com/ => this is my target.. this is the platform to hack… the information we have is that it is a Trust Fund as said in the description we are looking to disable the capabilities of the corrupt politicians from growing their wealth….
Prime minister account => cf3f7b26–7cf5–4334–9f6a-8afc078b3492 offshore account => 5e318aad-1720–47d5-ae5b-0c9c2161201f So with this information, the fst flag was hid in the file it self … i was able to get it… i checked the metadata of the attachment with the exiftool command as shown below.

metadata of the attachment
I found that it had some zipped information and when i unziped it.. i found another directory called docx_extract. so i used the command below and got the fst flag grep -R “GoH” docx_extract

the -R is for recursiveness… it checks through the whole directory for the pattern
2. Next question was the name of the culprit Let’s fst study the website and exhaust all the information we can get about these guys We have the CEO, the chief technology & innovation officer, chief finance officer, chief risk, compliance and governance officer and the manager… which of these can be a weak link ??? hmmmmm…. I read through some blogs and the highly targeted people are mostly the CEOs and the managers.. so i tried there names and they failed… problem is that i was copy pasting.. when i removed the last ‘s’ from the manager’s name, I got the flag right.
3.The next question is asking for: what is the name of the method you will use to build a clear, structured understanding of who or what you are attacking before you touch any tools. When the police is making a persona of there persons of interest, they go through a phase called profiling.. this involves making profile on the person of interest and this was the answer… pretty easy right?? But had to go through some blogs and alot of AI prompts for that.
Now we have the information below… — the target platform => http://lindensennational.com/ — the person of interest => Amelia Anderson — the method we use to know the person => profiling..
4.The next question was asking for the attacking vector that we are going to use : lets dig some more information about what profiling is and how to do it. One of the fundamental information we also have is the email address of the manager… **amelia.n.andersons@gmail.com** I think this might get us some important information… lets see made quite alot of searches about the lady and it seems the internet knows nothing about her… so this means we have to completely forcus on the website. I really tried my best to look for some information about this woman and turns out i couldn’t find much important info… but i found a blog on the website that was given and below it is.
In private banking, it’s easy for life to feel like a never-ending cycle of meetings, reviews, and deadlines. But over the years, I’ve learned something important: work is just one part of who we are, and the moments outside the office often shape us the most.
When I’m not at Lindsen National Bank working with clients and supporting our Trust Fund operations, I try to stay connected to the hobbies that keep me grounded. Some weekends I’m out with my camera, capturing small moments during my walks around the city. Other days, I’m at the community library reading with children who are just discovering the joy of books.
I also love experimenting with new things — exploring AI tools and small automation agents has become a surprising creative outlet for me. It’s a fun way to understand where technology is heading and how it may change the way we work.
And of course, my slower hobbies matter just as much. Baking, gardening, tasting new coffee roasts, even picking up my guitar when I have a quiet evening — these things remind me to breathe, reset, and live fully.
Life doesn’t end when the laptop closes. If anything, that’s when the meaningful parts begin.
My advice? Make space for the things that make you feel human. Work will always be there; balance won’t create itself.
This has some useful information… that might help us get the hobbies… passowrds and more. Well, this was not the end of it all… we had to make more research… below is the profile we have about the target — Job => works in private banking/Trust fund operations at lindsen National bank and she is as well the manager — Hobbies => photography, reading at the community library, exploiting ai tools and this is critical, baking, gardening, tasting new coffee roasts, playing guitar
The small automation agents is a massive red flag after alot of research, i found out that the best attack vector that we have according to the hint we had in the challenge that goes “when everything fails”.. the answer was around the human vector.. i tried spear phishing and it was rejected.. then i tried GoH{Phishing} which was accepted. — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — —
That was all for the OSINT challs. Now we were proceeding to the big boys.
The Pentest: 5.The next challenge is asking for the password and username of the culprit… Remember the culprit is the manager, so lets start cooking Brooooo!! this one was hard.. as we were trying to hack, we found out that the wp-admin was out of scope and the lnbank will not work… so we try something else… most of our password are in the website… lets see this one is a big chall man, No wonder it was given 300 damn!!.. Unlike the fst ones.. this one is hard this flag gave me some hard time. Jokingly, i decided to try and send a mail to Mrs Andersons’ email address… i thought this would not work in any way possible suprisingly, i got a ping back … this was hulaalaa…. man at this time i had to make sure that any next step i make… she has to buy my idea, click in a link and get me those creds… i fst had to look for a good tool to use and a better message to send… after some ample research, i got a tool called zphisher… git clone https://github.com/htr-tech/zphisher.git cd zphisher chmod +x zphisher.sh ./zphisher.sh After setting that… i made some nice research about the tool, i made sure that i get it running.. i used google as the template and i used cloud flared for the public url.. i then started my attack i had fst aked her if she was interested in the automation tool that i had.. and asked her to send me a message so i send her the demo link … remember in the information we got when profiling… she likes exploring automating agents… and this lead to everything. below is what i sent “Hello Amelia,
Thank you for your interest! I represent SecureAutomate Financial Technologies.
We specialize in AI-powered anomaly detection and automated compliance monitoring for financial institutions. Our CDR analyzer can integrate seamlessly with your existing systems.
You can access the demonstration portal and trial version here: https://emission-columns-trains-teams.trycloudflare.com
The demo will show real-time transaction monitoring and automated reporting features. Please use your bank login credentials to access the test environment.
Looking forward to your feedback!
Best regards, Semu kyc Tech Solutions Specialist” And as i was looking for ways of quiting, she tapped into the link and entered the credentials as shown below:

was able to watch Mrs. Amelia enter the creds
This was a relief… with my brain burning, i submitted the flag…
6.The next question was asking for a flag… The flag was somewhere in the website.. i just had to check every point of it… guess what.. i failed. i was sooo very tired… as the rules say, its not the end of the world.. decided to go out… attend prayers and then came back… cursor moved to the loans tab and the details of the fst account had the flag… this was cool… felt like a superstar.

the flag was in the loans tab
6.One last chall to submit … they want us to make a transfer from one account to another, include our email address and get the flag emailed to us let us see how cook this is. Now according to the attachment we downloaded, we had to make a transaction from the prime ministers account to the offshore account. Both of these accounts were given to us in the attachment that was provided, the one we used to solve the fst challenge checkpoint1. Well this one was easy. When you try to make a transaction on the website, u can only make that transaction with the accounts u have permissions to. But then it is possible for the manager to send money from an account they have access to, to another account and in this case it is the offshore account. So this is what i did. Using burpsuite, i intercepted the data that was sent in the transmission and changed the destination account.
- Intercept the transfer as shown below

intercept the traffic
use ctrl+r to send the packet to repeater and then change the “to_account_id” to the offshore id that was provided in the attachment as shown below.

change the destination to the offshore and leave the sorce as is
Since the transaction is successful, the flag will be sent to the email address u used in the description.
thanks for reading
메타데이터
- post_id
- ebfd6b7fff0a
- slug
- h4k-it2025-the-bankheist2-writeu-ebfd6b7fff0a
- url
- https://medium.com/@mudiuth/h4k-it2025-the-bankheist2-writeu-ebfd6b7fff0a
- canonical_url
- https://medium.com/@mudiuth/h4k-it2025-the-bankheist2-writeu-ebfd6b7fff0a
- author_url
- https://medium.com/@mudiuth
- status
- ok
- fetched_at
- 2026-07-15 04:57:40