Thai Broadband Provider Hacked via Fortinet Vulnerability

A high-profile hacking incident has unfolded in Thailand, targeting the systems of 3BB, one of the country’s largest broadband providers. The attack leveraged multiple vulnerabilities in Fortinet and F5 products to gain access to 3BB’s internal networks, compromising millions of users’ sensitive information.

The hacking operation was discovered after the attackers left behind a treasure trove of tools and scripts in an open directory hosted on infrastructure in Thailand. Hunt.io, the cybersecurity firm that uncovered the breach, identified over 298 files across 30 subdirectories, including exploitation scripts, brute-force and privilege escalation tools, credential harvesting scripts, and an inventory of compromised machines.

The attackers specifically crafted these tools for 3BB (Triple T Broadband), which was previously owned by Jasmine. Initial access was obtained through careful fingerprinting of a FortiGate SSL-VPN endpoint using eight shell scripts designed to determine the appliance’s firmware version, probe for vulnerabilities, and deploy exploits. The hackers then deployed an exploit targeting CVE-2024-21762 to achieve remote code execution (RCE).

The threat actor simultaneously executed reconnaissance operations against 3BB’s F5 BIG-IP instance and internal sales agent portal. Following initial access, the hackers attempted to gain root privileges on multiple Linux systems using PwnKit and Dirty COW exploits and a dedicated SUID backdoor installer.

After establishing persistent remote access using MeshCentral as a command-and-control (C&C) platform for remote administration, the attackers used various scripts to move laterally across the internal 3BB environment. They attempted to extract sensitive information, including SSH keys, PHP configurations, database credentials, SNMP community strings, and Radius authentication data.

The threat actor’s intentions were not limited to exploitation; they also executed a script designed to remove artifacts associated with vulnerability exploitation and backdoor deployment, as well as system logs. This suggests an effort to conceal the intrusion while ensuring continued remote access to compromised systems.

This incident highlights the importance of maintaining up-to-date software and patching vulnerabilities in critical infrastructure components. Moreover, it underscores the need for organizations to regularly review their network configurations and monitor for suspicious activity to prevent lateral movement by attackers.

If you’re a security administrator or IT professional responsible for managing your organization’s networks and systems, this incident serves as a reminder to stay vigilant about potential vulnerabilities and implement robust security measures to protect against similar attacks.


Source: SecurityWeek — 2026-09-15