Skip to content
Thai Broadband Provider Hacked via Fortinet Vulnerability

Thai Broadband Provider Hacked via Fortinet Vulnerability

Securityweek September 15, 2026

A threat actor targeted multiple vulnerabilities in Fortinet and F5 products to gain access to Thai broadband provider 3BB’s systems, Hunt.io reports.

The attack was discovered after the hackers left their intrusion arsenal in an open directory hosted on infrastructure in Thailand.

The directory contained 298 files across 30 subdirectories: multiple exploitation scripts, brute-force and privilege escalation tools, credential harvesting scripts, an inventory of compromised machines, and a MeshCentral instance agent configured as a persistent backdoor.

“The files were tagged across operational categories such as Exploit, Victim, Config, and History, consistent with an active staging environment,” Hunt.io notes .

The tools, the cybersecurity firm says, were crafted specifically for 3BB (Triple T Broadband), one of the largest providers of fixed-line broadband services in Thailand, with millions of users, and Jasmine, the company that previously owned Triple T Broadband.

Initial access was obtained through careful fingerprinting of a FortiGate SSL-VPN endpoint using eight shell scripts designed to determine the appliance’s firmware version, probe for vulnerabilities, and deploy exploits.

The attackers scanned for bugs such as CVE-2018-13379 , CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 , confirmed the instance’s firmware version, and deployed an exploit targeting CVE-2024-21762 to achieve remote code execution (RCE).

Simultaneously, the threat actor executed a reconnaissance operation against the victim’s F5 BIG-IP instance, probing for multiple vulnerabilities, including CVE-2021-22986 , CVE-2022-1388 , and CVE-2023-46747 , and against 3BB’s internal sales agent portal, running behind the load balancer.

Following initial access, the hackers attempted to gain root privileges on multiple Linux systems using PwnKit and Dirty COW exploits and a dedicated SUID backdoor installer.

“After successful host compromise, the actor established persistent remote access using MeshCentral as a command-and-control (C&C) platform for remote administration,” Hunt.io says.

, the attackers used various scripts for host discovery, remote access, and credential harvesting to move laterally across the internal 3BB environment.

They attempted to extract SSH keys, PHP configurations, database credentials, SNMP community strings, and Radius authentication data, and to perform passwordless MySQL authentication against internal databases.

Additionally, the threat actor used two scripts “to read sensitive files, deploy PHP web shells, inject SSH keys, and modify database privileges, providing multiple mechanisms for persistence and lateral movement across the environment,” Hunt.io notes.

Finally, the attackers executed a script designed to remove artifacts associated with vulnerability exploitation and backdoor deployment, along with the PHP web shells, MeshCentral deployment scripts, and system logs.

“The script concludes by verifying that persistence mechanisms remain operational, including checking the hidden SUID binary and confirming the MeshCentral service is still running. This demonstrates that the cleanup process was intended to conceal the intrusion while ensuring continued remote access to compromised systems,” Hunt.io says.

Related: 240,000 Hit by Data Breach at Japan’s Digital Agency

Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Related: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Related: PaperCut Flaws Exploited in AI-Powered Attacks

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Personal, Financial Info Exposed in Revolut Data Breach

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

GitLab Vulnerability Exploited One Day After Disclosure

Check Point Patches Critical VPN Vulnerabilities

Surfshark Systems Targeted by Hackers

Exein Secures $270M at $1.7B Valuation for Physical AI Security

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

240,000 Hit by Data Breach at Japan’s Digital Agency

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

Hacked HBO Max Account Used for Malware Delivery via ClickFix Attack

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Flipboard Whatsapp Whatsapp Email