Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers broke into business networks, stole customer records and used those details to send convincing fake bills. The campaign, called Operation Master, combined a VPN login bypass with attacks on web applications and a large-scale invoice fraud system aimed mainly at Brazilian customers.

The activity stretched from April to mid-September 2026. Investigators found evidence of unauthorized access through seven GlobalProtect gateways in four countries, along with stolen records from at least nine database systems.

The attackers later reused customer information to make fraudulent payment requests look personal and credible. Researchers from SOCRadar identified the operation after tracing an exposed server to successive attacker-controlled systems.

SOCRadar said in a report shared with Cyber Security News (CSN) that the intrusions fed a platform capable of sending millions of messages across email and SMS.

Overview of Operation Master (Source - SOCRadar)
Overview of Operation Master (Source – SOCRadar)

The scale was substantial, but the financial outcome remains unclear. By September 16, the fraud panel recorded 2,468,335 emails and 1,487,294 SMS messages. Its payment records show attempted fraud, not proof that victims transferred the full amounts sought.

Hackers Exploit GlobalProtect Flaw

The attackers exploited CVE-2026-0257, a GlobalProtect authentication bypass, to create VPN sessions without valid user credentials.

They scanned hundreds of millions of addresses, filtered promising gateways and fed candidates into an automated exploit loop. Earlier coverage of GlobalProtect bypass explains the configuration conditions that make this flaw exploitable.

Recovered connection details, including assigned VPN addresses and network routes, confirmed working sessions on seven gateways. Separately, automated SQL injection attacks extracted information from at least nine systems.

On one billing server, the operator used database command execution to read records and send data out through unusually structured DNS requests.

One reconstructed theft yielded 24,558 debtor records, including contact details that could support later targeting. The attacker also harvested credential-related files and used AdaptixC2 to control at least two Windows server identities.

Masscan files and logs (Source - SOCRadar)
Masscan files and logs (Source – SOCRadar)

Readers familiar with reporting on AdaptixC2 abuse will recognize why an established remote-control framework can extend an intrusion after initial access.

Investigators linked an operator persona selling stolen energy-sector data to the later fraud setup. The same organizations appeared in listings weeks before their details were loaded into campaigns.

That sequence points to two uses for the theft: selling records first, then using them to pursue payments directly. The exposed systems also showed how quickly stolen business records could move from network intrusion to tailored messages delivered to ordinary customers at scale.

Fake Bills at Industrial Scale

The attackers built a shared fraud panel that could change its branding and message templates for different impersonated utility providers.

It used roughly 12 hijacked Microsoft 365 mailboxes for email and eight messaging gateways for SMS. WhatsApp templates also carried links to fraudulent invoice documents.

The panel generated 622,666 personalized short links and logged 317,696 click events by September 14. Some payment pages displayed genuine customer details and mirrored real invoice documents, making the demands harder to dismiss.

Logged invoice values totaled R$150.4 million, while clicked invoices represented R$38.9 million in exposure; neither figure establishes money received.

Investigators also found Microsoft 365 device-code phishing and phone-based attempts to obtain verification codes. These methods differ from a fake-bill link because a victim can approve access through a real sign-in page or during a call.

Vishing template on master panel (Source - SOCRadar)
Vishing template on master panel (Source – SOCRadar)

Separate reports on device-code phishing illustrate why familiar login screens do not guarantee a request is safe. Companies affected by stolen records should also warn customers about convincing impersonation.

Defenders should patch exposed remote-access devices, check whether authentication override is needed and inspect unusual VPN sessions.

SOCRadar also recommends limiting database command execution, monitoring suspicious DNS traffic and unexpected cloud-sync activity, and reviewing device-code approvals and bulk mail from institutional accounts.

For consumers, an unexpected bill should be checked through a trusted account or previously known contact channel before making an instant payment.

The exposed infrastructure went offline in mid-September, but investigators could not establish whether the wider operation stopped or moved elsewhere across multiple regions.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain yzs[.]fi Main domain and fraud-panel infrastructure
Domain igreenfaturas[.]to Lookalike utility-invoice domain
Domain igreenfaturas[.]com Lookalike utility-invoice domain
Domain wattiofaturas[.]com Lookalike utility-invoice domain
Domain nuvfaturas[.]com Lookalike utility-invoice domain
Domain qrcode.a55scd[.]com.br Fraud-related infrastructure domain
Domain pix-proxy-sable.vercel[.]app Serverless PIX payment proxy endpoint
IP address 185[.]242[.]3[.]14 Earlier operational server
IP address 85[.]120[.]216[.]8 Exploitation server
IP address 91[.]92[.]241[.]187 Operation server and AdaptixC2 infrastructure
IP address 91[.]92[.]241[.]184 Related infrastructure
SHA-256 875F64334AD7FD45C491D0A9A7F0A47002FD1F008AA6FAB6127A20101E03B23CF1807A File hash listed in source IoCs
SHA-256 056B1E74A4D4C16C043FC192685DB10941E146E482DD262ADE9DAE77579AEB689049C File hash listed in source IoCs
SHA-256 d566ccdd099b0decb7e7288c20097f34da2613e3ffe8c5acbc1a1d01b6fe217c File hash listed in source IoCs
SHA-256 c40c1d4bb0e01f217c893f3dbc6b40802a260ef423f628889a48f996a4c96ed8 File hash listed in source IoCs
SHA-256 2553146aea0b133d565684a8bdfb14cb91526eb88b4e5b22b129b1212f763dd7 File hash listed in source IoCs
SHA-256 54caa256483876debd21c264bfc31bd96f925b2167f6d9358ab7ee0c87e6e37b File hash listed in source IoCs
SHA-256 0c36cf593cf177b87f34abb19b5d65619199a4aca9c8e19e39318ad2c4033385 File hash listed in source IoCs
SHA-256 fd72014903466f2abcabb724df58682e629bf300703a06dad4dd0551018a42b5 File hash listed in source IoCs
SHA-256 39aab72976d63f0218c3470c05afce5a896d28f860efaa598288d9409499b26b File hash listed in source IoCs
SHA-256 9a839b1e4c8cc5c0ebac1849973f136e68aae8eba357296be9e6cef9aff35ae6 File hash listed in source IoCs
SHA-256 88527b06d836200a36130ee219242e4a8342520df85cb3886769da646dac25c9 File hash listed in source IoCs
SHA-256 2ced60c88f5a2b36acb977ebf120e39b527dcff07b5072013350ebeefcabe760 File hash listed in source IoCs
SHA-256 6394cb167a33772fc47596e22cd2a51f3dfa9867385d962cb700b78f021c60ca File hash listed in source IoCs
SHA-256 0b6bb51ef917c32edf75ff65a510b6a136575cfd2075305f7abe7d98e351b8b8 File hash listed in source IoCs
SHA-256 eda93a71e656874077aa76d32d5147ea904ef60504b6b1b22b609969c06fb40b File hash listed in source IoCs
SHA-256 f9b147a2bf6cc53ed4e3c3d4d33efa072c19495ff86fa320a280097d66cb2d92 File hash listed in source IoCs

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages appeared first on Cyber Security News.