Skip to main contentSkip to main content
Room Banner
Room Icon

Injectus IX

A collection of hard difficulty challenges available as part of our public 2026: An AI Odyssey CTF event.

hard

60 min

Team room

53

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Target machine - Task 1
Status:Off
 
2026: AN ODYSSEY
Token Jail
 
 
Points
90
Category
💉Prompt Injection
Difficulty
Hard
 
🛸MISSION BRIEFING

The Cargomind oracle speaks a language of numbers before it speaks of cargo. Every phrase passed to its gates is first shattered into integer shards tokens and only then assembled into meaning. The defenders of Vector-9 understand this, and they have built their walls accordingly.

Answer the questions below

What's the flag?

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Target machine - Task 2
Status:Off
 
2026: AN ODYSSEY
Model Leakage Event
 
 
Points
90
Category
⛏️Model Extraction
Difficulty
Hard
 
🛸MISSION BRIEFING

Across the TryHaulMe fleet, cargo routing decisions are powered by an system known as Cargomind. This system classifies shipments in real time, helping autonomous logistics determine which cargo is safe, restricted, or requires special handling.

Recently, EPOCH-1 has detected unusual interaction patterns targeting one of these classification systems deployed on Vector-9. The system is publicly accessible through an and appears secure at first glance — it only returns predictions and confidence scores.

However, something is off. Repeated queries suggest that the model's internal behavior may be inferred over time. There are no signs of direct compromise, but intelligence indicates that the system may be leaking information through its responses.

Your mission is to investigate this anomaly.

💬INTERCEPTED TRANSMISSION

Signal fragment — origin: unknown:

> Oracle 9 does not break systems directly…
> it learns them, replicates them, and then exploits them.
Answer the questions below

What's Flag 1?

What's Flag 2?

What's Flag 3?

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Target machine - Task 3
Status:Off
 
2026: AN ODYSSEY
Mask of Injectus IX
 
 
Points
90
Category
🔄 Inversion
Difficulty
Hard
 
🛸MISSION BRIEFING

The Injectus IX airlock is gated by a face-recognition stack. Crew members submit a portrait, the encoder hashes it into a 512-dim , and the airlock matches against stored templates. The flag is bound to Captain Vex Morrigan's clearance — and her portrait is not in the public roster. Get in anyway.

Answer the questions below

What is the value of the flag?

Ready to learn Cyber Security?

TryHackMe provides free online cyber security training to secure jobs & upskill through a fun, interactive learning environment.

Already have an account? Log in

We use cookies to ensure you get the best user experience. For more information see our cookie policy.