Hackers exploit FortiGate flaw to breach Thai ISP 3BB

Hackers used a FortiGate SSL‑VPN flaw to access Thai broadband provider 3BB, then deployed multiple Fortinet and F5 exploits, a MeshCentral backdoor and left 298 files exposed, Hunt.io reports.

Hackers gained access to Thai broadband provider 3BB by exploiting a FortiGate SSL‑VPN vulnerability and left an exposed directory containing their tools, Hunt.io reports.

The open directory, hosted on infrastructure in Thailand, contained 298 files across 30 subdirectories. The files included exploitation scripts, brute‑force and privilege‑escalation tools, credential‑harvesting scripts, an inventory of compromised machines and a MeshCentral agent configured as a persistent backdoor. Hunt.io says the files were organized by operational categories consistent with an active staging environment.

Initial access was achieved after attackers fingerprinted a FortiGate SSL‑VPN endpoint using eight shell scripts designed to identify firmware versions, probe for weaknesses and deploy exploits. The intruders scanned for Fortinet vulnerabilities including CVE‑2018‑13379, CVE‑2022‑42475, CVE‑2023‑27997 and CVE‑2024‑21762, and used an exploit for CVE‑2024‑21762 to gain remote code execution. At the same time the actor performed reconnaissance against an F5 BIG‑IP instance, probing CVE‑2021‑22986, CVE‑2022‑1388 and CVE‑2023‑46747, and targeted an internal sales agent portal behind the site’s load balancer.

After gaining a foothold the attackers attempted to elevate privileges on multiple Linux hosts using public local exploits such as PwnKit and Dirty COW and a custom SUID backdoor installer. Once hosts were compromised, the intruders installed MeshCentral and used it as a command‑and‑control platform to maintain persistent remote access and administer systems.

The actor used scripts for host discovery, lateral movement and credential collection. Hunt.io observed attempts to extract SSH keys, PHP configuration files, database credentials, SNMP community strings and RADIUS authentication data, and to perform passwordless MySQL authentication against internal databases. Two scripts were used to read sensitive files, deploy PHP web shells, add SSH keys and change database privileges, enabling multiple persistence and lateral‑movement mechanisms.

At the end of operations the attackers executed a cleanup script that removed PHP web shells, MeshCentral deployment scripts and system logs while confirming persistence components remained. The routine checked for a hidden SUID binary and verified the MeshCentral service was still running, indicating the actors intended to conceal their activity while keeping access.

3BB, formally Triple T Broadband, is one of Thailand’s largest fixed‑line broadband providers and was previously owned by Jasmine. Hunt.io reconstructed the intrusion chain from the exposed files and says many of the tools appeared built specifically for 3BB’s environment.

Articles by this author