Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Operation Master exploited GlobalProtect CVE-2026-0257, deployed AdaptixC2, and ran large-scale credential theft and invoice fraud.
Researchers detailed Operation Master, a cybercrime campaign that exploited CVE-2026-0257, an authentication-bypass flaw in Palo Alto Networks GlobalProtect portals and gateways. Palo Alto confirmed active exploitation and advised installing fixed PAN-OS or Prisma Access releases and disabling unneeded Authentication Override. The actor scanned 277.5 million addresses, selected 81 organizations, used SQL injection and xp_cmdshell for PowerShell execution, stole NTDS and registry hives, and deployed AdaptixC2. Stolen data fed a fraud platform that generated more than 2.4 million email and SMS messages and 622,666 phishing links before going offline in mid-September.
- CVE-2026-0257 lets unauthenticated attackers open GlobalProtect VPN sessions; Palo Alto confirmed exploitation.
- Automated scans of 277.5 million addresses produced a target list of 81 organizations.
- SQL injection and xp_cmdshell enabled PowerShell, credential dumping, and Kerberoasting.
- Attackers exfiltrated data with DNS tunneling, prepared rclone sync, and staged SFTP of SQL backups.
- A fraud panel sent over 2.4 million emails and SMS using 622,666 phishing links.
Vulnerabilities mentionedAll →
- CVE-2026-02577.896%Authentication Bypass in Palo Alto Networks PAN-OS GlobalProtect Portal and Gatewaypublished · Palo Alto Networks PAN-OS (GlobalProtect portal and gateway) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | yzs.fi | rkstation backup, to the fraud-panel infrastructure and the yzs[.]fi domain. Operation Master underscores a broader shift: vul |
Full article766 words · extracted from gbhackers.com · click to collapse
“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform.
The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware.
The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto Networks GlobalProtect portal and gateway deployments.
The flaw can enable unauthenticated attackers to establish unauthorized VPN sessions when vulnerable configurations are present.
Palo Alto Networks has confirmed active exploitation and recommends applying fixed PAN-OS or Prisma Access releases and disabling Authentication Override where it is not required.security.
Recovered tooling shows an automated workflow that fingerprinted exposed VPN infrastructure, generated authentication-override material.
Submitted it to the GlobalProtect authentication endpoint, and harvested tunnel configuration details including assigned IP addresses, routes, DNS settings, and IPsec parameters.
The intrusion chain was not technically novel, but its automation was significant: masscan logs recorded 277.5 million scanned addresses across 22 files, producing a curated target set of 81 organizations.
The adversary’s activity extended well beyond perimeter access. SQL injection campaigns against Brazilian SaaS, CRM, financial, support, and education platforms yielded raw database dumps from at least nine environments.
In several cases, the actor progressed from time-based SQL injection to operating-system command execution by abusing Microsoft SQL Server’s xp_cmdshell feature.
This enabled PowerShell execution under SQL Server service identities and created a path for internal discovery, credential theft, lateral movement, and covert data extraction.

One verified intrusion produced SAM, SYSTEM, and SECURITY registry hives alongside an Active Directory ntds.dit database, assets that can support offline credential cracking and domain-level compromise.
The toolkit also included Kerberoasting and AS-REP roasting components, Evil-WinRM activity, token impersonation tooling, reverse tunnels, Redis module-loading utilities, and exploits associated with local privilege escalation and application-server access.
AdaptixC2 Deployment
A key operational feature was redundant exfiltration. STRU observed continuous DNS tunneling from a compromised cloud-hosted Windows server, with more than 470,000 DNS queries used to transmit encoded data.
STRU assessed that, the actor used the vulnerability to obtain access through seven GlobalProtect gateways in four countries.
Executed low-and-slow password spraying against M365 environments using localized and seasonal patterns to avoid account lockouts.
The traffic reportedly exposed debtor records and SHA-1 password hashes from an energy-billing environment.

The actor also prepared rclone-based synchronization to cloud storage, configured to transfer databases, credentials, configuration files, documents, and other sensitive file types. A third mechanism involved staged SFTP transfers of SQL Server backup files.
For command and control, the operation deployed the open-source AdaptixC2 framework on infrastructure associated with 91[.]92[.]241[.]187.
AdaptixC2 describes itself as a modular red-team framework and supports the Gopher listener and agent components recovered in the operation.
STRU found Windows and Linux beacon artifacts, reflective shellcode, and a custom loader designed to decrypt payloads, patch AMSI and ETW, perform process injection, detect analysis environments, and delete itself after execution.
The criminal business model was equally notable. After selling stolen corporate and energy-sector information through the “masterblack” persona on underground forums, the actor repurposed the same records to populate a multi-tenant phishing and invoice-fraud engine.

The panel generated more than 2.4 million email and SMS messages and maintained 622,666 personalized phishing links before it went offline in mid-September.
The platform used domainless Microsoft 365 OAuth device-code lures, phone-guided vishing, password spraying, and localized invoice templates to evade traditional email-security controls.
Infrastructure exposure ultimately linked operational stages to the email address cyberkill2025[@]gmail.com, which appeared across reconnaissance-service registrations, AI-assisted development workspaces, attack tooling, and leaked database records.
The actor’s operational-security failures allowed researchers to follow the chain from an exposed exploitation server at 85[.]120[.]216[.]8, through a workstation backup, to the fraud-panel infrastructure and the yzs[.]fi domain.
Operation Master underscores a broader shift: vulnerabilities traditionally leveraged for espionage or ransomware access are being operationalized as repeatable inputs for fraud ecosystems.
Organizations running GlobalProtect should urgently identify exposed portals and gateways, install Palo Alto Networks’ fixed releases.
Review Authentication Override settings and certificate reuse, examine VPN session logs for unauthorized connections, and hunt for DNS-tunneling patterns, abnormal xp_cmdshell activity, rclone execution, and AdaptixC2-related artifacts.
Panorama and Cloud NGFW are not affected by CVE-2026-0257, according to the vendor advisory.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.