SOCRadar reported that the alleged Operation Master cybercrime operation chained enterprise intrusion, data theft, underground data sales, and invoice fraud. Active from April through mid-September 2026, the operators reportedly exploited Palo Alto Networks GlobalProtect authentication-bypass flaw CVE-2026-0257, alongside SQL-injection and other web attacks, to compromise seven gateways across four countries and exfiltrate data from at least nine databases. The group allegedly used AdaptixC2, DNS tunneling, staged SFTP transfers, and rclone cloud synchronization for command-and-control and data theft, then sold stolen customer and billing records under the “masterblack” persona.
The stolen data was reportedly repurposed into a Brazilian utility-bill impersonation platform that created personalized payment links and distributed an estimated 2.4 million email and SMS messages, with additional WhatsApp lures reported. The campaigns used stolen customer details and mirrored invoices to drive PIX payments through attacker-controlled infrastructure. SOCRadar assessed with high confidence that “masterblack” and cyberkill2025@gmail.com were tied to a principal operator; while the infrastructure went offline in mid-September, investigators could not determine whether the operation ended or relocated.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
By September 16, the fraud panel recorded 2,468,335 emails and 1,487,294 SMS messages sent using hijacked Microsoft 365 mailboxes and messaging gateways. Logged invoice values totaled R$150.4 million, though this did not establish that attackers received the funds.
By September 14, the master-panel invoice-fraud platform had generated 622,666 personalized short links and recorded 317,696 click events. The platform impersonated utility brands and used email, SMS, and WhatsApp to deliver fraudulent invoice links.
The exposed infrastructure associated with Operation Master went offline in mid-September 2026. Investigators could not determine whether the operation had ceased or moved to new infrastructure.
Operation Master began operating in April 2026, combining enterprise-network intrusion, theft of customer data, and utility-invoice fraud primarily targeting Brazilian customers.
SOCRadar linked the masterblack persona and cyberkill2025@gmail.com to sales of stolen Wattio Energy and iGreen Energy data. The stolen customer and billing data was subsequently used to personalize utility-invoice phishing campaigns.
The operators exploited CVE-2026-0257 to establish unauthorized VPN sessions through seven GlobalProtect gateways in four countries. They also used automated SQL injection against at least nine database systems and exfiltrated data, including 24,558 debtor records from a Brazilian energy-billing system via DNS tunneling.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.