🧩 TTX
Cyber Advanced 90 min

Ransomware Attack on City Government

A sophisticated ransomware attack (PLAY ransomware group) has infiltrated the City of Georgetown's municipal network through a phishing campaign targeting the finance department. The attack encrypts critical servers including tax databases, utility billing systems, permit management, and emergency services dispatch. The ransomware group exfiltrated 2TB of sensitive citizen data before encryption and is now demanding M in Monero. City employees are locked out of email, file shares, and all line-of-business applications. The attack was detected when the IT helpdesk received over 200 calls within 30 minutes about ransom notes appearing on screens across multiple departments. The city's SOC team identified that the initial access occurred 14 days ago via a spear-phishing email with a malicious Excel attachment (DragonEgg Loader). The threat actors have established persistence via scheduled tasks, created multiple admin accounts, disabled Windows Defender across 800 endpoints, and used Cobalt Strike beacons for C2 communication. Data exfiltration was detected to 5 external IPs with over 2TB of data transferred in the last 72 hours.

🎯 Objectives

📋 Exercise Modules

  1. MODULE 1: Initial Detection & Triage (15 min) — Assess the alert, determine scope, activate IR team, engage external IR firm
  2. MODULE 2: MITRE ATT&CK Mapping & Analysis (20 min) — Map full attack chain to MITRE ATT&CK, identify security gaps, prioritize containment
  3. MODULE 3: Containment & Eradication (20 min) — Isolate network segments, preserve evidence, remove threat actor access, block C2 infrastructure
  4. MODULE 4: Ransom Decision & Stakeholder Communication (20 min) — Ransom payment decision, legal consultation, public communication strategy
  5. MODULE 5: Recovery & Restoration (15 min) — Prioritize system recovery, validate backups, restore from clean backups, implement security improvements

💬 Discussion Questions

📚 References

← All Scenarios