Post

Hack'OSINT CTF 2025

Hack'OSINT CTF 2025

OSINT

Interview

Solvers: xxx
Author: hack-osint

Description

The previous document suggests that the interview given by Charlottle is a good starting point.
Can you find out when this interview conducted?

Flag format: JJ/MM/AAAA

Solution

When doing this challenge, they provide a document file for us to read and had some information related to the entire challenge.
Start reading and I found a twitter account @CN_CumSpe

twitter_account

Look around the post and found this one:

twitter_post

This post is posted on Feb 2, 2025

Flag: 02/02/2025

Qui es-tu?

Solvers: xxx
Author: hack-osint

Description

In the interview, Charlotte mentions the name of a person who behaved suspiciously towards her.
Would you be able to identify this person for us?

Flag format: Henri le Montclair

Solution

When I look at this post:

twitter_post

I thought A is the first letter of the person she trying to mention.
Look back the document and found this:

document document

Thinking that Alpha and Ainoa Fernandez is the right answer, result is wrong.
Then I found this charlotte.nectoux Medium page

Found the profile of the guy that interviewed her:

medium_profile

His profile Marc Steiner

Go around and found this conversation:

medium_conversation

So the person she trying to mention is Nicolas de Richelieu

Flag: Nicolas de Richelieu

Pseudonyme

Solvers: xxx
Author: hack-osint

Description

This Nicolas seems very active on social media. Can you find out what username he goes by?

Flag format: xhacker

Solution

I search for his page facebook and found this:

facebook_page

Check for his reel and found this one really interesting:

facebook_reel

Quite blur, zoom it out.

facebook_reel_zoom

Yes, got his username.

Flag: Xnicolasht

Première approche

Solvers: xxx
Author: hack-osint

Description

While investigating this pseudonym, you uncover a place filled with secrets that was meant to remain confidential.
Can you determine exactly when Nicolas began communication (a former member of APT-509 arrested in 2024)?

Flag format: JJ/MM/AAAA

Solution

I use his username to search and found this Bluesky account:

bluesky_account

His profile xnicolasht.bsky.social
Found a post that contains a drive link:

bluesky_post

But when zoom it out, there is a missing part.

bluesky_post_zoom

Use this image to text to convert the image to text.

image_to_text

Need to figure out that first part of .fr/drive/#/2/drive/view/f3YGBpPsdLVDxwpvH+PfWsHBS2nNHpOglwGr-VP9cHI/

I try to find and the result is that I can not find it and so on the challenge ended =((.

Flag: JJ/MM/AAAA

After all, this CTF challenge is pretty cool with nice OSINT flow. Definitely gonna try this challenge next year.

Got the badge, awesome!

badge

badge

This post is licensed under CC BY 4.0 by the author.