A Thai Broadband Provider’s Systems Compromised by Sophisticated Attackers
Thailand’s largest broadband provider, 3BB (Triple T Broadband), has fallen victim to a highly complex and targeted cyberattack. The attackers exploited multiple vulnerabilities in Fortinet and F5 products to gain unauthorized access to the company’s systems, compromising millions of users’ sensitive information.
The attack was discovered after the hackers left their intrusion arsenal in an exposed directory hosted on infrastructure in Thailand. This careless mistake allowed cybersecurity researchers at Hunt.io to uncover a treasure trove of malicious tools and scripts designed specifically for 3BB. The directory contained over 298 files across 30 subdirectories, including exploitation scripts, brute-force and privilege escalation tools, credential harvesting scripts, and an inventory of compromised machines.
The attackers’ modus operandi was to carefully fingerprint a FortiGate SSL-VPN endpoint using shell scripts that determined the appliance’s firmware version, probed for vulnerabilities, and deployed exploits. They targeted known vulnerabilities such as CVE-2018-13379, CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762, confirming the instance’s firmware version before deploying an exploit targeting CVE-2024-21762 to achieve remote code execution (RCE). Simultaneously, they executed a reconnaissance operation against the victim’s F5 BIG-IP instance, probing for multiple vulnerabilities.
Once initial access was obtained, the hackers attempted to gain root privileges on multiple Linux systems using PwnKit and Dirty COW exploits and a dedicated SUID backdoor installer. They then established persistent remote access using MeshCentral as a command-and-control (C&C) platform for remote administration. Next, they used various scripts for host discovery, remote access, and credential harvesting to move laterally across the internal 3BB environment.
The attackers’ intentions were clear: to extract sensitive information from the compromised systems. They attempted to extract SSH keys, PHP configurations, database credentials, SNMP community strings, and Radius authentication data, as well as perform passwordless MySQL authentication against internal databases. Furthermore, they used two scripts to read sensitive files, deploy PHP web shells, inject SSH keys, and modify database privileges.
What’s most concerning about this attack is the attackers’ attention to detail and their ability to conceal their tracks. The cleanup script executed by the hackers was designed to remove artifacts associated with vulnerability exploitation and backdoor deployment, as well as system logs. This demonstrates a level of sophistication that should send alarm bells ringing for organizations worldwide.
The takeaway from this incident is clear: no organization is immune to cyberattacks, regardless of size or complexity. Organizations must prioritize cybersecurity and invest in robust threat detection systems, regular software updates, and employee education to prevent similar attacks. Moreover, it’s essential to implement a vulnerability management program that proactively identifies and patches known vulnerabilities before they can be exploited by attackers. By taking these steps, organizations can significantly reduce the risk of falling victim to sophisticated cyberattacks like this one.
Source: SecurityWeek — 2026-09-15