A cyber attack exploiting multiple vulnerabilities in Fortinet and F5 products has compromised the systems of the Thai broadband provider 3BB, according to a report by Hunt.io. This breach highlights the ongoing threat to telecommunications firms from sophisticated cyber actors.
Discovery and Tools Used
The intrusion was uncovered when the attackers’ tools were found in an open directory on a server located in Thailand. This directory contained 298 files across 30 subdirectories and included scripts for exploitation, privilege escalation, and credential harvesting, as well as a MeshCentral agent configured for persistent access.
These tools were custom-made for 3BB, a major broadband provider in Thailand, and its former owner, Jasmine. The attackers initially gained access by targeting a FortiGate SSL-VPN endpoint with eight shell scripts to identify vulnerabilities in the system’s firmware.
Exploited Vulnerabilities
Upon confirming the firmware version, the attackers exploited several known vulnerabilities, including CVE-2018-13379, CVE-2022-42475, CVE-2023-27997, and particularly CVE-2024-21762, to achieve remote code execution. They also conducted reconnaissance on the F5 BIG-IP system, targeting vulnerabilities like CVE-2021-22986 and CVE-2022-1388.
Following initial access, the attackers worked to gain root privileges on various Linux systems using known exploits like PwnKit and Dirty COW. They established persistent remote access via MeshCentral, allowing ongoing control over the compromised systems.
Post-Compromise Activities
After securing access, the threat actors used a range of scripts for host discovery and lateral movement within 3BB’s infrastructure. They harvested credentials, extracted SSH keys, and modified database privileges, enhancing their control over the network.
Efforts to maintain persistence included deploying PHP web shells and injecting SSH keys. The attackers also ran a cleanup script to erase traces of their presence, while ensuring their backdoor mechanisms remained operational.
This attack underscores the importance of vigilance and robust cybersecurity measures in defending against sophisticated threats targeting critical infrastructure.
