Meridian Malware

Welcome to Meridian Bank. On paper it’s a mid-sized retail and corporate bank – millions of accounts, an online banking platform, ATMs, a SWIFT gateway, and a SOC that never sleeps. In this village, you’re on the inside, and the job splits two ways. Pick your side. 

You can come join our Blue Team! Meridian has been hit before – and it left marks. You get the real thing: samples pulled from actual incidents that struck the bank’s environment, banking ransomware caught in phishing waves, and many more to come. Your job is to crack them open and answer the questions the SOC needs: what did it do, how did it get in, what did it touch, and how do we detect the next one? Static triage, sandbox detonation, unpacking, and writing the detection that turns one incident into lasting defense. 

On the other side of the room we have the Red Team that builds. You craft new malware – droppers, evasive payloads, C2 that blends into normal traffic – and put it up against a live replica of Meridian’s infrastructure. Can you slip past the EDR, move laterally toward the core banking systems, and reach the vault without the blue side catching you? Everything you build gets tested, scored, and dissected by the team across the table. 

Two teams. One bank. Which side are you on?

Goal of the Competition
– Blue side: Reverse engineer the binaries handed out at the stand and be ready to explain your answers when the organizers come around and ask about each sample – what it does, how it hides, how it persists, how you’d catch it. 
– Red side: Bypass the EDR, AV, and any other defenses standing in your way, then encrypt a single file picked by us on-site. A file counts as encrypted only if you change both its extension and its contents. 
– Work through the challenges we put in front of you, ask for hints if you’re stuck , and go as deep as you can.
Rules of Engagement

– Bring yourself and a laptop, everything else you need is provided at the stand. 

– The competition runs in rounds with a limited number of seats per round, so sign up to reserve your slot. 

– Each player gets their own isolated instance of the target – no attacking other players, other seats, or shared infrastructure. 

– Points are awarded per challenge. Hints are available so ask the organizers. 

– Ties are broken by furthest progress, then by time, then by fewest hints used. 

– Rules are not static. Organizers may adjust, add, or clarify rules during the competition – check in with us if you’re unsure. Our word is final. 

– No tool restrictions. Use anything you want: your own scripts, public tooling, custom loaders, whatever gets the job done. If you wrote it the night before, even better. 

– No DoS / DDoS. No flooding, no resource exhaustion, no crashing the environment for everyone else. Break in, don’t break things. 

– Don’t destroy the infrastructure. You’re allowed to compromise the target – you’re not allowed to wipe it, brick it, or leave it in a state where the next player can’t play. If you’re not sure whether an action crosses that line, ask first. 

– No teaming, no flag sharing, no solution sharing during the competition. Watching over a shoulder, passing hints between seats, or coordinating between rounds is cheating. Talk shop all you want after the round ends. 

– No tampering with other players’ progress or with the flags/samples once found – no hiding, moving, or modifying them for anyone else. 

– Scope is what we tell you it is. The organizers will define scope before each round (which machines, which segments, which samples). Touching anything outside scope – including the venue’s own network, other DefCamp infrastructure, or the internet at large – is an instant disqualification. 

– Respect privacy. Any data you come across in the challenges stays in the challenges. Don’t post it, don’t exfiltrate it off the stand, don’t share it. 

– Responsible disclosure. If you find a bug or vulnerability we didn’t plant, tell us. Don’t weaponize it against the environment or against DefCamp itself. 

– Comply with the law. Local, national, international – all of it applies. If it would be illegal outside this room, it’s illegal inside this room too. 

– Stay civil. Trash talk is fine, disrespect toward other players, organizers, or DefCamp staff is not. Same goes for the stand itself – treat the hardware like it’s yours. 

– Time’s up means time’s up. When the round ends, hands off the keyboard. 

– Violations can mean anything from a warning, to point deductions, to being pulled from the round, to a ban from future editions. Organizers decide. 

– Meridian Malware is meant to be hard but fair. Play smart, play mean, play clean.

PRIZES

TBD

SPONSORED BY