Threat actors targeted Fortinet and F5 vulnerabilities to compromise Thai broadband provider 3BB and related systems, using a staged arsenal that included exploit scripts, privilege escalation tools, credential harvesters, and a MeshCentral backdoor. The attackers fingerprinted appliances, exploited CVE-2024-21762 for remote code execution, moved laterally inside the environment, and then tried to erase evidence while preserving persistence. #Fortinet #F5 #3BB #TripleTBroadband #MeshCentral #CVE-2024-21762
Keypoints
- The attack targeted 3BB, one of Thailandβs largest broadband providers.
- Openly hosted files exposed the attackersβ staging environment and toolset.
- The threat actor probed FortiGate SSL-VPN and F5 BIG-IP flaws for initial access.
- CVE-2024-21762 was exploited to achieve remote code execution.
- MeshCentral, web shells, and stolen credentials were used for persistence and lateral movement.
Read More: https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/