Hackers broke into business networks, stole customer records and used those details to send convincing fake bills. The campaign, called Operation Master, combined a VPN login bypass with attacks on web applications and a large-scale invoice fraud system aimed mainly at Brazilian customers.
The activity stretched from April to mid-September 2026. Investigators found evidence of unauthorized access through seven GlobalProtect gateways in four countries, along with stolen records from at least nine database systems.
The attackers later reused customer information to make fraudulent payment requests look personal and credible. Researchers from SOCRadar identified the operation after tracing an exposed server to successive attacker-controlled systems.
SOCRadar said in a report shared with Cyber Security News (CSN) that the intrusions fed a platform capable of sending millions of messages across email and SMS.
The scale was substantial, but the financial outcome remains unclear. By September 16, the fraud panel recorded 2,468,335 emails and 1,487,294 SMS messages. Its payment records show attempted fraud, not proof that victims transferred the full amounts sought.
Hackers Exploit GlobalProtect Flaw
The attackers exploited CVE-2026-0257, a GlobalProtect authentication bypass, to create VPN sessions without valid user credentials.
They scanned hundreds of millions of addresses, filtered promising gateways and fed candidates into an automated exploit loop. Earlier coverage of GlobalProtect bypass explains the configuration conditions that make this flaw exploitable.
Recovered connection details, including assigned VPN addresses and network routes, confirmed working sessions on seven gateways. Separately, automated SQL injection attacks extracted information from at least nine systems.
On one billing server, the operator used database command execution to read records and send data out through unusually structured DNS requests.
One reconstructed theft yielded 24,558 debtor records, including contact details that could support later targeting. The attacker also harvested credential-related files and used AdaptixC2 to control at least two Windows server identities.
.webp)
Readers familiar with reporting on AdaptixC2 abuse will recognize why an established remote-control framework can extend an intrusion after initial access.
Investigators linked an operator persona selling stolen energy-sector data to the later fraud setup. The same organizations appeared in listings weeks before their details were loaded into campaigns.
That sequence points to two uses for the theft: selling records first, then using them to pursue payments directly. The exposed systems also showed how quickly stolen business records could move from network intrusion to tailored messages delivered to ordinary customers at scale.
Fake Bills at Industrial Scale
The attackers built a shared fraud panel that could change its branding and message templates for different impersonated utility providers.
It used roughly 12 hijacked Microsoft 365 mailboxes for email and eight messaging gateways for SMS. WhatsApp templates also carried links to fraudulent invoice documents.
The panel generated 622,666 personalized short links and logged 317,696 click events by September 14. Some payment pages displayed genuine customer details and mirrored real invoice documents, making the demands harder to dismiss.
Logged invoice values totaled R$150.4 million, while clicked invoices represented R$38.9 million in exposure; neither figure establishes money received.
Investigators also found Microsoft 365 device-code phishing and phone-based attempts to obtain verification codes. These methods differ from a fake-bill link because a victim can approve access through a real sign-in page or during a call.
.webp)
Separate reports on device-code phishing illustrate why familiar login screens do not guarantee a request is safe. Companies affected by stolen records should also warn customers about convincing impersonation.
Defenders should patch exposed remote-access devices, check whether authentication override is needed and inspect unusual VPN sessions.
SOCRadar also recommends limiting database command execution, monitoring suspicious DNS traffic and unexpected cloud-sync activity, and reviewing device-code approvals and bulk mail from institutional accounts.
For consumers, an unexpected bill should be checked through a trusted account or previously known contact channel before making an instant payment.
The exposed infrastructure went offline in mid-September, but investigators could not establish whether the wider operation stopped or moved elsewhere across multiple regions.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | yzs[.]fi | Main domain and fraud-panel infrastructure |
| Domain | igreenfaturas[.]to | Lookalike utility-invoice domain |
| Domain | igreenfaturas[.]com | Lookalike utility-invoice domain |
| Domain | wattiofaturas[.]com | Lookalike utility-invoice domain |
| Domain | nuvfaturas[.]com | Lookalike utility-invoice domain |
| Domain | qrcode.a55scd[.]com.br | Fraud-related infrastructure domain |
| Domain | pix-proxy-sable.vercel[.]app | Serverless PIX payment proxy endpoint |
| IP address | 185[.]242[.]3[.]14 | Earlier operational server |
| IP address | 85[.]120[.]216[.]8 | Exploitation server |
| IP address | 91[.]92[.]241[.]187 | Operation server and AdaptixC2 infrastructure |
| IP address | 91[.]92[.]241[.]184 | Related infrastructure |
| SHA-256 | 875F64334AD7FD45C491D0A9A7F0A47002FD1F008AA6FAB6127A20101E03B23CF1807A | File hash listed in source IoCs |
| SHA-256 | 056B1E74A4D4C16C043FC192685DB10941E146E482DD262ADE9DAE77579AEB689049C | File hash listed in source IoCs |
| SHA-256 | d566ccdd099b0decb7e7288c20097f34da2613e3ffe8c5acbc1a1d01b6fe217c | File hash listed in source IoCs |
| SHA-256 | c40c1d4bb0e01f217c893f3dbc6b40802a260ef423f628889a48f996a4c96ed8 | File hash listed in source IoCs |
| SHA-256 | 2553146aea0b133d565684a8bdfb14cb91526eb88b4e5b22b129b1212f763dd7 | File hash listed in source IoCs |
| SHA-256 | 54caa256483876debd21c264bfc31bd96f925b2167f6d9358ab7ee0c87e6e37b | File hash listed in source IoCs |
| SHA-256 | 0c36cf593cf177b87f34abb19b5d65619199a4aca9c8e19e39318ad2c4033385 | File hash listed in source IoCs |
| SHA-256 | fd72014903466f2abcabb724df58682e629bf300703a06dad4dd0551018a42b5 | File hash listed in source IoCs |
| SHA-256 | 39aab72976d63f0218c3470c05afce5a896d28f860efaa598288d9409499b26b | File hash listed in source IoCs |
| SHA-256 | 9a839b1e4c8cc5c0ebac1849973f136e68aae8eba357296be9e6cef9aff35ae6 | File hash listed in source IoCs |
| SHA-256 | 88527b06d836200a36130ee219242e4a8342520df85cb3886769da646dac25c9 | File hash listed in source IoCs |
| SHA-256 | 2ced60c88f5a2b36acb977ebf120e39b527dcff07b5072013350ebeefcabe760 | File hash listed in source IoCs |
| SHA-256 | 6394cb167a33772fc47596e22cd2a51f3dfa9867385d962cb700b78f021c60ca | File hash listed in source IoCs |
| SHA-256 | 0b6bb51ef917c32edf75ff65a510b6a136575cfd2075305f7abe7d98e351b8b8 | File hash listed in source IoCs |
| SHA-256 | eda93a71e656874077aa76d32d5147ea904ef60504b6b1b22b609969c06fb40b | File hash listed in source IoCs |
| SHA-256 | f9b147a2bf6cc53ed4e3c3d4d33efa072c19495ff86fa320a280097d66cb2d92 | File hash listed in source IoCs |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

