Thai Broadband Provider Hacked via Fortinet Vulnerability

Thai Broadband Provider Hacked via Fortinet Vulnerability
Threat actors targeted Fortinet and F5 vulnerabilities to compromise Thai broadband provider 3BB and related systems, using a staged arsenal that included exploit scripts, privilege escalation tools, credential harvesters, and a MeshCentral backdoor. The attackers fingerprinted appliances, exploited CVE-2024-21762 for remote code execution, moved laterally inside the environment, and then tried to erase evidence while preserving persistence. #Fortinet #F5 #3BB #TripleTBroadband #MeshCentral #CVE-2024-21762

Keypoints

  • The attack targeted 3BB, one of Thailand’s largest broadband providers.
  • Openly hosted files exposed the attackers’ staging environment and toolset.
  • The threat actor probed FortiGate SSL-VPN and F5 BIG-IP flaws for initial access.
  • CVE-2024-21762 was exploited to achieve remote code execution.
  • MeshCentral, web shells, and stolen credentials were used for persistence and lateral movement.

Read More: https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/