Overview of Operation Master | Image: SOCRadar Threat Research Unit
Fake energy bills went out to Brazilian customers more than 2.4 million times this summer. Each one carried the victim’s real name, due date, and power usage. According to SOCRadar’s investigation into Operation Master, those details came from data a single suspected operator allegedly stole in earlier network breaches.
At a Glance
| Actor | Forum persona “masterblack” (suspected principal operator) |
| Activity | Network intrusion, data theft and sale, automated invoice fraud |
| Targets | Energy and utility firms and their customers, mostly in Brazil |
| Scale | 21 organizations compromised; data from 600+ companies; R$150.4M in fake invoices issued (claimed, not confirmed losses) |
| Law enforcement | No arrests or charges announced |
| Sources | SOCRadar Threat Research Unit; Palo Alto Networks Unit 42 |
TL;DR
A threat actor allegedly broke into corporate networks through a Palo Alto GlobalProtect flaw and SQL injection. The actor first sold stolen utility databases on a forum. Weeks later, the same records reportedly powered a fake-invoice platform that sent millions of emails and texts.
What Happened
Breaking In at Scale
Operation Master ran from April 23 to mid-September 2026. The operator scanned about 277.5 million addresses to find weak VPN gateways. Next, a custom script picked out vulnerable GlobalProtect setups. An exploit loop with 30 workers then hit each candidate.
The main entry point was CVE-2026-0257, an authentication bypass in GlobalProtect. Palo Alto’s Unit 42 has confirmed attacks in the wild against non-SAML setups. SOCRadar found live VPN sessions on 7 gateways in four countries. Still, the researchers stress that the method itself was not new. “The core advancement is its automated industrial scaling rather than novel exploitation mechanics,” the report notes.
SQL Injection and Data Theft
At the same time, the actor ran SQL injection campaigns against Brazilian web apps. On SQL Server, the attacker switched on a built-in command feature to gain shell access. From there, the operator moved to nearby servers and pulled Windows credential stores. One energy billing system allegedly leaked 24,558 debtor records through DNS tunneling.
For command and control, the actor used the open-source AdaptixC2 framework. Logs showed at least two Windows servers under active control. Stolen files left through DNS queries and a cloud sync tool.
Inside the Invoice Fraud Machine
The second stage of the scheme was a web app the operator called “master-panel.” It works like a small SaaS product for invoice fraud. Each “tenant” copies a real Brazilian energy brand, with its own lookalike domain, logo, and templates.
The panel sent mail through about 12 hijacked Microsoft 365 mailboxes. This gave the emails real sender reputations. Meanwhile, eight bulk SMS gateways and WhatsApp templates carried the same lure. Each link opened a bill built from the victim’s own data. Payment went through PIX, Brazil’s instant payment system, via a serverless proxy.
Unfortunately, speed favors the attacker here. “PIX payments settle rapidly, significantly narrowing the window for fraud detection and recovery,” SOCRadar warns.
Who Is Behind It
SOCRadar links the operation to a forum persona called “masterblack.” One Gmail address appeared in the actor’s tools, test data, exploit scripts, and OSINT accounts. A leaked hacker forum database then tied that address to the masterblack account. That account had listed stolen iGreen Energy and Wattio data for sale weeks before the fraud began.
Based on this overlap, SOCRadar assesses “with High Confidence” that masterblack is a principal operator. However, this is a research finding, not a court ruling. No authority has named or charged a suspect.
An AI Co-Developer
The operator also relied on an AI coding agent with more than 36 offensive subagents. The AI reportedly wrote exploit drivers and exfiltration scripts. Recovered transcripts show the operator framing requests as authorized pentesting. Ironically, the report says “the AI’s refusal responses ultimately provided key evidence against the actor.”
Impact and Scale
SOCRadar counts 21 compromised organizations, 16 of them in Brazil. It also found stolen data tied to more than 600 companies. Energy and utilities make up about 420 of those. The fraud panel generated 622,666 personalized links and logged 317,696 clicks.
The money figures need care. The links carried R$150.4 million in fake invoices, and clicked links opened R$38.9 million. Yet the report states these “represent attempted and exposed fraud metrics rather than confirmed stolen funds.” In other words, nobody yet knows how much cash victims actually paid.
How to Stay Protected
Operation Master shows how one breach can feed invoice fraud for months. Defenders can take several steps now:
- Patch GlobalProtect for CVE-2026-0257 or apply Palo Alto’s workarounds. Review VPN logs for odd sessions.
- Disable SQL Server command execution features unless a system truly needs them.
- Watch for long, encoded DNS queries and unexpected cloud sync traffic.
- Lock down Microsoft 365 mailboxes with MFA and alert on sudden sending spikes.
- Utilities should monitor for lookalike billing domains and warn customers through official channels.
Consumers should also treat any “bill due today” text with suspicion. Instead of clicking, open the provider’s app or website directly to check the balance.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!