A newly uncovered cybercrime campaign shows how a single threat actor turned enterprise network breaches into a full-scale, automated invoice fraud operation, first selling stolen data on hacker forums and then repurposing it to scam hundreds of thousands of victims directly.
SOCRadar’s Threat Research Unit has detailed “Operation Master,” a campaign active from April to mid-September 2026 that exploited a GlobalProtect authentication bypass (CVE-2026-0257) to breach seven VPN gateways across four countries.
The actor ran masscan sweeps covering 277.5 million hosts across 22 logged runs, narrowing targets to 81 high-value organizations before pivoting into SQL injection attacks that abused “xp_cmdshell” to convert database access into full remote command execution.
Hackers Exploit GlobalProtect Flaw

Confirmed breaches hit at least nine database systems, yielding customer records, wallet data, password hashes, and financial credentials.
Command and control ran on a self-compiled AdaptixC2 framework hosted at 91.92.241.187, using stock “Gopher” beacon agents with minimal custom evasion; an AES-encrypted loader was the only bespoke component.
Notably, the operator relied on an AI coding agent with 36-plus offensive subagents to write intrusion tooling, including exploit drivers and exfiltration scripts, while handling the fraud-panel code personally.
Recovered AI refusal logs show the operator disguising malicious requests as “authorized penetration testing” transcripts that ultimately became evidence against them.
Stolen data left victim networks through two redundant channels: continuous DNS tunneling that logged 470,268 queries from a single compromised system, and automated rclone syncs to cloud storage filtering roughly 140 sensitive file types.
Offline credential theft included SAM, SYSTEM, and SECURITY registry hives plus a full Active Directory database, enabling deeper lateral movement across compromised networks.
The campaign’s second act was a multi-tenant “master-panel” application impersonating Brazilian utility brands like iGreen and Wattio through lookalike domains.
It generated 622,666 personalized phishing links embedding real customer names, invoice amounts, and due date details pulled straight from the earlier breaches, representing R$150.4 million in attempted fraud, with R$38.9 million exposed via victim clicks.
Delivery spanned hijacked Microsoft 365 mailboxes, eight SMS gateways, and WhatsApp Business templates, while payments were collected through Brazil’s PIX system via a serverless proxy that obscures the total funds actually stolen.
Researchers linked the operation with high confidence to an individual using the email cyberkill2025@gmail.com and the forum alias “masterblack,” tracing the same identifier across leaked forum databases, OSINT tool registrations, and penetration-test documentation.
Forum posts show the actor sold stolen iGreen and Wattio data weeks before launching the phishing campaigns against those same customers, confirming a deliberate two-stage monetization pipeline.
The infrastructure went dark in mid-September after operational security lapses exposed it, though researchers caution the actor may simply have relocated.
SOCRadar recommends organizations patch remote-access appliances immediately, disable unnecessary OAuth device-code flows, restrict database command execution, and treat unsolicited PIX-linked invoices as inherently suspicious, since instant-payment fraud leaves almost no window for recovery.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.