securityonline.info 29 Sept 2026, 07:06 UTC

Hackers Exploited GlobalProtect Flaw to Fuel Brazilian Invoice Fraud

Hackers Exploited GlobalProtect Flaw to Fuel Brazilian Invoice Fraud
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

SOCRADAR Threat Research Unit, with input from Palo Alto Networks Unit 42, has tied a global intrusion campaign—Operation Master—to Brazilian invoice fraud that used stolen utility data to generate fake energy bills. The operation reportedly ran from 23 April to mid‑September 2026, breaking in via automated scanning of 277.5 million addresses to locate vulnerable GlobalProtect VPNs, then exploiting CVE-2026-0257, an authentication bypass in GlobalProtect for non‑SAML configurations.

The attacker reportedly conducted SQL injection campaigns in Brazilian web applications, gaining shell access on SQL Server and exfiltrating Windows credential stores, with one energy-billing system allegedly leaking 24,558 debtor records via DNS tunneling. The same records were later used to power a “master-panel” web app, a SaaS‑like platform for issuing fake invoices.

The fraud pipeline used about 12 hijacked Microsoft 365 mailboxes to deliver emails, and eight bulk SMS gateways plus WhatsApp templates to push links to victims. Each “tenant” imitated real Brazilian energy brands with lookalike domains, and the bills were constructed from victims’ own data. Payments allegedly flowed through PIX via a serverless proxy, with the speed of PIX reducing detection windows.

SOCRadar links the operation to a forum persona “masterblack,” plus an AI coding agent that produced exploit and exfiltration scripts; the research notes the AI’s refusal responses ultimately provided key evidence. Reported impact includes 21 compromised organisations and data tied to 600+ companies, with R$150.4 million in fake invoices linked to the activity; however, these figures are described as fraud metrics rather than confirmed losses.

Defenders are urged to patch CVE-2026-0257, monitor for DNS‑tunneled data, disable unnecessary SQL Server command features, MFA‑protect Microsoft 365 mailboxes, and warn consumers about lookalike billing domains.

View full article

Article by CyberSIXT