Operation Master (SOCRadar 24 Sep / CSN 28 Sep): GlobalProtect auth bypass CVE-2026-0257 → AdaptixC2 + 2.4M invoice-fraud messages
SOCRadar Threat Research Unit (STRU; published 24 September 2026; Cybersecurity News amplified 28 Sep) documents Operation Master (April–mid-September 2026): a multi-tier intrusion and monetization pipeline that exploited Palo Alto Networks PAN-OS GlobalProtect authentication bypass CVE-2026-0257 to establish unauthorized VPN sessions on seven gateways in four countries, combined with web-app/SQL attacks (incl. xp_cmdshell), AdaptixC2 on at least two Windows servers, DNS tunneling / rclone exfil, and an automated invoice-fraud panel. Fraud telemetry cited: 2,468,335 emails and 1,487,294 SMS by 16 Sep; 622,666 personalized links; targeting skewed to Brazilian payment/PIX workflows; energy-sector data also sold under forum persona “masterblack”. Recon: ~277.5M address scans → 81 high-value orgs; 9+ databases stolen. Vendor PSIRT CVE-2026-0257 (published 13 May 2026, updated 3 Jun): auth bypass on GlobalProtect portal/gateway when authentication-override cookies are enabled with a specific certificate configuration; Panorama and Cloud NGFW not impacted; Exploit Maturity ATTACKED; limited exploit attempts on unpatched devices without mitigations. Primary: Palo Alto PSIRT; campaign: SOCRadar; wire: CSN.
- Product
- Palo Alto Networks PAN-OS GlobalProtect portal/gateway (Prisma Access also listed); not Panorama / Cloud NGFW
- Versions
- Affected when GlobalProtect portal/gateway has authentication-override cookies enabled with the specified cert config — PAN-OS 12.1 < 12.1.4-h6 / < 12.1.7; 11.2 < 11.2.4-h17 / < 11.2.7-h14 / < 11.2.10-h7 / < 11.2.12; 11.1 < 11.1.4-h33 / < 11.1.6-h32 / < 11.1.7-h6 / < 11.1.10-h25 / < 11.1.13-h5 / < 11.1.15; 10.2 < 10.2.7-h34 / < 10.2.10-h36 / < 10.2.13-h21 / < 10.2.16-h7 / < 10.2.18-h6; Prisma Access 11.2 / 10.2 trains below listed hotfix. Fixed: upgrade to vendor-listed hotfix or later (e.g. 12.1.4-h6 / 12.1.7, 11.2.12, 11.1.15, 10.2.18-h6 paths). Workaround: dedicated auth-override cookie cert or disable Authentication Override.
- CVSS
- HIGH (Palo Alto CVSS 4.0 BT/B; Exploit Maturity ATTACKED); NVD CVSS 3.1 9.1 Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/S:U/C:H/I:H/A:N (NVD) - Exploited in Australia?
- unknown
- Patch to
- Upgrade PAN-OS / Prisma Access to vendor-listed fixed builds for CVE-2026-0257; or disable Authentication Override / use a dedicated auth-override cookie certificate per PSIRT. Hunt unauthorized GlobalProtect sessions, AdaptixC2, DNS tunneling, rclone sync, and invoice-fraud mail/SMS from institutional accounts; rotate credentials/certs that traversed exposed gateways
Primary: Palo Alto Networks PSIRT — CVE-2026-0257 GlobalProtect authentication bypass (13 May 2026; updated 3 Jun) · Vendor: Palo Alto Networks — CVE-2026-0257 (vendor advisory) · CVE: CVE-2026-0257 · SOCRadar STRU — Operation Master intrusion/monetization pipeline (24 Sep 2026)
