BUG BROS
We break systems so you don't have to. Competitive CTF team, security researchers, and relentless hackers pushing the boundaries of cybersecurity.
The Team.
Meet the minds behind the exploits. Each member brings unique expertise to the battlefield.
Shadow
Binary exploitation specialist. Turns buffer overflows into root shells since 2019.
Phantom
Web exploitation and reconnaissance expert. If it's online, Phantom already found it.
Cipher
Breaks ciphers for breakfast. From RSA to lattice-based attacks β nothing stays encrypted for long.
Glitch
Firmware, malware, game hacks β Glitch reads binaries like novels and writes patches like poetry.
Nexus
Digital forensics investigator. Recovers deleted evidence and traces attack chains with surgical precision.
Vex
Cloud misconfiguration hunter. AWS, GCP, Azure β no cloud is safe from Vex's enumeration scripts.
Zero
Android and iOS app security researcher. Breaks mobile apps and finds zero-days in SDKs.
Spectre
The human firewall tester. Spectre's phishing campaigns have a 94% click rate in red team ops.
Events.
Upcoming competitions, past victories, and community meetups.
DEF CON CTF Qualifiers
The biggest stage in competitive hacking. We're preparing for qualifiers with daily training sessions focused on pwn and kernel exploitation.
Google CTF 2026
Google's annual CTF featuring cutting-edge challenges in web, crypto, and hardware security. 48 hours of pure adrenaline.
PicoCTF 2026
Mentored 15 beginners through the competition. Three of our mentees placed in the top 500 globally.
HTB University CTF
A 3-day intense competition against university teams worldwide. Our team solved 28/32 challenges.
Real World CTF Quals
Participated in one of the hardest CTFs globally. Focused on IoT exploitation and blockchain challenges.
Writeups.
Detailed breakdowns of challenges we've cracked. Learn from our approach.
Heap Overflow in libxml2
Exploiting a use-after-free vulnerability in the XML parser to achieve remote code execution on the challenge server.
JWT Algorithm Confusion
Breaking a JWT-based authentication system by switching the algorithm from RS256 to HS256, using the public key as the HMAC secret.
Lattice-Based Crypto Attack
Using LLL reduction to break a custom lattice-based encryption scheme by exploiting small error terms in the implementation.
Android APK Reverse Engineering
Decompiling a CTF challenge APK to extract hardcoded API keys and bypass certificate pinning for flag retrieval.
Memory Forensics β Volatility3
Extracting credentials and browsing history from a Windows memory dump using Volatility3 plugins and custom YARA rules.
AWS S3 Bucket Misconfiguration
Enumerating and exploiting overly permissive S3 bucket policies to access sensitive internal documents in a cloud CTF challenge.
CTF Challenges.
Practice challenges created by our team. Test your skills.
Biometric Authentication
A futuristic biometric login system protects this endpoint. Can you find a way to bypass the authentication and capture the flag?
Shadow Injection
A vulnerable web application with multiple injection points. Escalate from SQLi to full server compromise.
Kernel Panic
A custom Linux kernel module with a subtle vulnerability. Exploit it to escalate privileges and read the root flag.
Biometric Authentication
SECURE ACCESS TERMINAL v2.4.1
Contact.
Want to join the team, collaborate, or just say hello? Reach out.
Get in Touch
We're always looking for passionate hackers who want to level up their skills. Whether you're a beginner or a seasoned CTF player, there's a place for you on the team.
- π§ contact@bugbros.online
- π¬ Discord: discord.gg/bugbros
- π¦ Twitter: @bugbros_ctf
- π GitHub: github.com/bugbros
- π CTFtime: ctftime.org/team/bugbros