SYSTEM ACTIVE β€” ALL UNITS OPERATIONAL

BUG BROS

We break systems so you don't have to. Competitive CTF team, security researchers, and relentless hackers pushing the boundaries of cybersecurity.

bugbros@kali:~
0+
CTFs Played
0
Podium Finishes
0+
Flags Captured
0
Team Members

The Team.

Meet the minds behind the exploits. Each member brings unique expertise to the battlefield.

SH

Shadow

// Team Lead & Pwn

Binary exploitation specialist. Turns buffer overflows into root shells since 2019.

PH

Phantom

// Web & OSINT

Web exploitation and reconnaissance expert. If it's online, Phantom already found it.

CX

Cipher

// Cryptography

Breaks ciphers for breakfast. From RSA to lattice-based attacks β€” nothing stays encrypted for long.

GL

Glitch

// Reverse Engineering

Firmware, malware, game hacks β€” Glitch reads binaries like novels and writes patches like poetry.

NX

Nexus

// Forensics & DFIR

Digital forensics investigator. Recovers deleted evidence and traces attack chains with surgical precision.

VX

Vex

// Cloud & Infrastructure

Cloud misconfiguration hunter. AWS, GCP, Azure β€” no cloud is safe from Vex's enumeration scripts.

ZR

Zero

// Mobile Security

Android and iOS app security researcher. Breaks mobile apps and finds zero-days in SDKs.

SP

Spectre

// Social Engineering

The human firewall tester. Spectre's phishing campaigns have a 94% click rate in red team ops.

Events.

Upcoming competitions, past victories, and community meetups.

AUG 2026 β€” UPCOMING

DEF CON CTF Qualifiers

The biggest stage in competitive hacking. We're preparing for qualifiers with daily training sessions focused on pwn and kernel exploitation.

Registered
JUL 2026 β€” UPCOMING

Google CTF 2026

Google's annual CTF featuring cutting-edge challenges in web, crypto, and hardware security. 48 hours of pure adrenaline.

Preparing
MAY 2026

PicoCTF 2026

Mentored 15 beginners through the competition. Three of our mentees placed in the top 500 globally.

Completed β€” Top 50
MAR 2026

HTB University CTF

A 3-day intense competition against university teams worldwide. Our team solved 28/32 challenges.

3rd Place
JAN 2026

Real World CTF Quals

Participated in one of the hardest CTFs globally. Focused on IoT exploitation and blockchain challenges.

Top 100

Writeups.

Detailed breakdowns of challenges we've cracked. Learn from our approach.

πŸ“

Heap Overflow in libxml2

Exploiting a use-after-free vulnerability in the XML parser to achieve remote code execution on the challenge server.

Pwn Hard
πŸ‘€ Shadow πŸ“… May 2026
πŸ“

JWT Algorithm Confusion

Breaking a JWT-based authentication system by switching the algorithm from RS256 to HS256, using the public key as the HMAC secret.

Web Medium
πŸ‘€ Phantom πŸ“… Apr 2026
πŸ“

Lattice-Based Crypto Attack

Using LLL reduction to break a custom lattice-based encryption scheme by exploiting small error terms in the implementation.

Crypto Hard
πŸ‘€ Cipher πŸ“… Mar 2026
πŸ“

Android APK Reverse Engineering

Decompiling a CTF challenge APK to extract hardcoded API keys and bypass certificate pinning for flag retrieval.

Rev Easy
πŸ‘€ Zero πŸ“… Feb 2026
πŸ“

Memory Forensics β€” Volatility3

Extracting credentials and browsing history from a Windows memory dump using Volatility3 plugins and custom YARA rules.

Forensics Medium
πŸ‘€ Nexus πŸ“… Jan 2026
πŸ“

AWS S3 Bucket Misconfiguration

Enumerating and exploiting overly permissive S3 bucket policies to access sensitive internal documents in a cloud CTF challenge.

Cloud Easy
πŸ‘€ Vex πŸ“… Dec 2025

CTF Challenges.

Practice challenges created by our team. Test your skills.

πŸ”

Biometric Authentication

A futuristic biometric login system protects this endpoint. Can you find a way to bypass the authentication and capture the flag?

Web Beginner
🏁 1 Flag πŸ“‚ Recon / Info Disclosure
πŸ•ΈοΈ

Shadow Injection

A vulnerable web application with multiple injection points. Escalate from SQLi to full server compromise.

Web Medium
🏁 3 Flags πŸ”’ Coming Soon
🧬

Kernel Panic

A custom Linux kernel module with a subtle vulnerability. Exploit it to escalate privileges and read the root flag.

Pwn Hard
🏁 2 Flags πŸ”’ Coming Soon
← Back to Challenges

Biometric Authentication

SECURE ACCESS TERMINAL v2.4.1

πŸ”

Contact.

Want to join the team, collaborate, or just say hello? Reach out.

Get in Touch

We're always looking for passionate hackers who want to level up their skills. Whether you're a beginner or a seasoned CTF player, there's a place for you on the team.