Skip to content
DnsLister Forum

Where domain hunters compare notes

Operation Master: GlobalProtect auth bypass (CVE-2026-0257) to a multi-tenant invoice fraud platform, same stolen data monetized twice

STRU published an analysis of a campaign that covers the whole chain: perimeter access, data theft, forum sales, and then automated fraud. What makes it interesting is that the same stolen assets were reused across both ways of making money. Access and recon: → CVE-2026-0257 (GlobalProtect auth bypass) used against 7 gateways in 4 countries → 277.5M address scans across 22 log files, filtered down to 81 target organizations Post-exploitation: → SQLi to RCE via xp_cmdshell, with 9+ database instances confirmed hit → SAM, SYSTEM, and SECURITY hives plus an AD database taken for offline use → AdaptixC2 as the C2, controlling at least 2 Windows server identities → Two redundant exfiltration channels: continuous DNS subdomain tunneling and automated rclone sync Initial phishing avoided domains entirely: M365 OAuth device-code phishing combined with phone-guided vishing, so there was nothing for email gateways to catch. Monetization: → Corporate and energy sector databases listed on a cybercrime forum under the persona "masterblack" → The same data then fed a multi-tenant invoice fraud engine: 2.4M+ email and SMS messages and 622,666 personalized links → Funds collected via PIX behind a serverless proxy. The receiving-side key material can't be recovered from this dataset. Attribution came from OPSEC mistakes. One operator email (cyberkill2025[@]https://hubs.la/Q04ym25c0) appeared in 5 operational contexts and matched the forum persona in leaked database records. The infrastructure went offline in mid-September 2026. Learn more: https://hubs.la/Q04ym1VP0

Source: r/u/socradario · by /u/socradario

Leave a Reply

Your email address will not be published. Required fields are marked *