Back Securityweek Thai Broadband Provider Hacked via Fortinet Vulnerability
A threat actor targeted multiple vulnerabilities in Fortinet and F5 products to gain access to Thai broadband provider 3BB’s systems, Hunt.io reports.
The attack was discovered after the hackers left their intrusion arsenal in an open directory hosted on infrastructure in Thailand.
The directory contained 298 files across 30 subdirectories: multiple exploitation scripts, brute-force and privilege escalation tools, credential harvesting scripts, an inventory of compromised machines, and a MeshCentral instance agent configured as a persistent backdoor.
“The files were tagged across operational categories such as Exploit, Victim, Config, and History, consistent with an active staging environment,” Hunt.io notes .
The tools, the cybersecurity firm says, were crafted specifically for 3BB (Triple T Broadband), one of the largest providers of fixed-line broadband services in Thailand, with millions of users, and Jasmine, the company that previously owned Triple T Broadband.
Initial access was obtained through careful fingerprinting of a FortiGate SSL-VPN endpoint using eight shell scripts designed to determine the appliance’s firmware version, probe for vulnerabilities, and deploy exploits.
The attackers scanned for bugs such as CVE-2018-13379 , CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 , confirmed the instance’s firmware version, and deployed an exploit targeting CVE-2024-21762 to achieve remote code execution (RCE).
Simultaneously, the threat actor executed a reconnaissance operation against the victim’s F5 BIG-IP instance, probing for multiple vulnerabilities, including CVE-2021-22986 , CVE-2022-1388 , and CVE-2023-46747 , and against 3BB’s internal sales agent portal, running behind the load balancer.
Following initial access, the hackers attempted to gain root privileges on multiple Linux systems using PwnKit and Dirty COW exploits and a dedicated SUID backdoor installer.
“After successful host compromise, the actor established persistent remote access using MeshCentral as a command-and-control (C&C) platform for remote administration,” Hunt.io says.
, the attackers used various scripts for host discovery, remote access, and credential harvesting to move laterally across the internal 3BB environment.
They attempted to extract SSH keys, PHP configurations, database credentials, SNMP community strings, and Radius authentication data, and to perform passwordless MySQL authentication against internal databases.
Additionally, the threat actor used two scripts “to read sensitive files, deploy PHP web shells, inject SSH keys, and modify database privileges, providing multiple mechanisms for persistence and lateral movement across the environment,” Hunt.io notes.
Finally, the attackers executed a script designed to remove artifacts associated with vulnerability exploitation and backdoor deployment, along with the PHP web shells, MeshCentral deployment scripts, and system logs.
“The script concludes by verifying that persistence mechanisms remain operational, including checking the hidden SUID binary and confirming the MeshCentral service is still running. This demonstrates that the cleanup process was intended to conceal the intrusion while ensuring continued remote access to compromised systems,” Hunt.io says.
Related: 240,000 Hit by Data Breach at Japan’s Digital Agency
Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Related: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Related: PaperCut Flaws Exploited in AI-Powered Attacks
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
Personal, Financial Info Exposed in Revolut Data Breach
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
GitLab Vulnerability Exploited One Day After Disclosure
Check Point Patches Critical VPN Vulnerabilities
Surfshark Systems Targeted by Hackers
Exein Secures $270M at $1.7B Valuation for Physical AI Security
Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
OpenAI Investigates Report Linking AI Agents to RubyGems Attack
240,000 Hit by Data Breach at Japan’s Digital Agency
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
Hacked HBO Max Account Used for Malware Delivery via ClickFix Attack
Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
