CyberSecurityNews

Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages


Hackers broke into business networks, stole customer records and used those details to send convincing fake bills. The campaign, called Operation Master, combined a VPN login bypass with attacks on web applications and a large-scale invoice fraud system aimed mainly at Brazilian customers.

The activity stretched from April to mid-September 2026. Investigators found evidence of unauthorized access through seven GlobalProtect gateways in four countries, along with stolen records from at least nine database systems.

The attackers later reused customer information to make fraudulent payment requests look personal and credible. Researchers from SOCRadar identified the operation after tracing an exposed server to successive attacker-controlled systems.

SOCRadar said in a report shared with Cyber Security News (CSN) that the intrusions fed a platform capable of sending millions of messages across email and SMS.

Overview of Operation Master (Source – SOCRadar)

The scale was substantial, but the financial outcome remains unclear. By September 16, the fraud panel recorded 2,468,335 emails and 1,487,294 SMS messages. Its payment records show attempted fraud, not proof that victims transferred the full amounts sought.

Hackers Exploit GlobalProtect Flaw

The attackers exploited CVE-2026-0257, a GlobalProtect authentication bypass, to create VPN sessions without valid user credentials.

They scanned hundreds of millions of addresses, filtered promising gateways and fed candidates into an automated exploit loop. Earlier coverage of GlobalProtect bypass explains the configuration conditions that make this flaw exploitable.

Recovered connection details, including assigned VPN addresses and network routes, confirmed working sessions on seven gateways. Separately, automated SQL injection attacks extracted information from at least nine systems.

On one billing server, the operator used database command execution to read records and send data out through unusually structured DNS requests.

One reconstructed theft yielded 24,558 debtor records, including contact details that could support later targeting. The attacker also harvested credential-related files and used AdaptixC2 to control at least two Windows server identities.

Masscan files and logs (Source - SOCRadar)
Masscan files and logs (Source – SOCRadar)

Readers familiar with reporting on AdaptixC2 abuse will recognize why an established remote-control framework can extend an intrusion after initial access.

Investigators linked an operator persona selling stolen energy-sector data to the later fraud setup. The same organizations appeared in listings weeks before their details were loaded into campaigns.

That sequence points to two uses for the theft: selling records first, then using them to pursue payments directly. The exposed systems also showed how quickly stolen business records could move from network intrusion to tailored messages delivered to ordinary customers at scale.

Fake Bills at Industrial Scale

The attackers built a shared fraud panel that could change its branding and message templates for different impersonated utility providers.

It used roughly 12 hijacked Microsoft 365 mailboxes for email and eight messaging gateways for SMS. WhatsApp templates also carried links to fraudulent invoice documents.

The panel generated 622,666 personalized short links and logged 317,696 click events by September 14. Some payment pages displayed genuine customer details and mirrored real invoice documents, making the demands harder to dismiss.

Logged invoice values totaled R$150.4 million, while clicked invoices represented R$38.9 million in exposure; neither figure establishes money received.

Investigators also found Microsoft 365 device-code phishing and phone-based attempts to obtain verification codes. These methods differ from a fake-bill link because a victim can approve access through a real sign-in page or during a call.

Vishing template on master panel (Source - SOCRadar)
Vishing template on master panel (Source – SOCRadar)

Separate reports on device-code phishing illustrate why familiar login screens do not guarantee a request is safe. Companies affected by stolen records should also warn customers about convincing impersonation.

Defenders should patch exposed remote-access devices, check whether authentication override is needed and inspect unusual VPN sessions.

SOCRadar also recommends limiting database command execution, monitoring suspicious DNS traffic and unexpected cloud-sync activity, and reviewing device-code approvals and bulk mail from institutional accounts.

For consumers, an unexpected bill should be checked through a trusted account or previously known contact channel before making an instant payment.

The exposed infrastructure went offline in mid-September, but investigators could not establish whether the wider operation stopped or moved elsewhere across multiple regions.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Domainyzs[.]fiMain domain and fraud-panel infrastructure
Domainigreenfaturas[.]toLookalike utility-invoice domain
Domainigreenfaturas[.]comLookalike utility-invoice domain
Domainwattiofaturas[.]comLookalike utility-invoice domain
Domainnuvfaturas[.]comLookalike utility-invoice domain
Domainqrcode.a55scd[.]com.brFraud-related infrastructure domain
Domainpix-proxy-sable.vercel[.]appServerless PIX payment proxy endpoint
IP address185[.]242[.]3[.]14Earlier operational server
IP address85[.]120[.]216[.]8Exploitation server
IP address91[.]92[.]241[.]187Operation server and AdaptixC2 infrastructure
IP address91[.]92[.]241[.]184Related infrastructure
SHA-256875F64334AD7FD45C491D0A9A7F0A47002FD1F008AA6FAB6127A20101E03B23CF1807AFile hash listed in source IoCs
SHA-256056B1E74A4D4C16C043FC192685DB10941E146E482DD262ADE9DAE77579AEB689049CFile hash listed in source IoCs
SHA-256d566ccdd099b0decb7e7288c20097f34da2613e3ffe8c5acbc1a1d01b6fe217cFile hash listed in source IoCs
SHA-256c40c1d4bb0e01f217c893f3dbc6b40802a260ef423f628889a48f996a4c96ed8File hash listed in source IoCs
SHA-2562553146aea0b133d565684a8bdfb14cb91526eb88b4e5b22b129b1212f763dd7File hash listed in source IoCs
SHA-25654caa256483876debd21c264bfc31bd96f925b2167f6d9358ab7ee0c87e6e37bFile hash listed in source IoCs
SHA-2560c36cf593cf177b87f34abb19b5d65619199a4aca9c8e19e39318ad2c4033385File hash listed in source IoCs
SHA-256fd72014903466f2abcabb724df58682e629bf300703a06dad4dd0551018a42b5File hash listed in source IoCs
SHA-25639aab72976d63f0218c3470c05afce5a896d28f860efaa598288d9409499b26bFile hash listed in source IoCs
SHA-2569a839b1e4c8cc5c0ebac1849973f136e68aae8eba357296be9e6cef9aff35ae6File hash listed in source IoCs
SHA-25688527b06d836200a36130ee219242e4a8342520df85cb3886769da646dac25c9File hash listed in source IoCs
SHA-2562ced60c88f5a2b36acb977ebf120e39b527dcff07b5072013350ebeefcabe760File hash listed in source IoCs
SHA-2566394cb167a33772fc47596e22cd2a51f3dfa9867385d962cb700b78f021c60caFile hash listed in source IoCs
SHA-2560b6bb51ef917c32edf75ff65a510b6a136575cfd2075305f7abe7d98e351b8b8File hash listed in source IoCs
SHA-256eda93a71e656874077aa76d32d5147ea904ef60504b6b1b22b609969c06fb40bFile hash listed in source IoCs
SHA-256f9b147a2bf6cc53ed4e3c3d4d33efa072c19495ff86fa320a280097d66cb2d92File hash listed in source IoCs

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link