Security researchers have discovered a sophisticated cyber attack targeting Thailand’s Triple T Broadband, which operates under the consumer brand 3BB. The breach was linked to a critical SSL-VPN vulnerability in FortiGate devices, allowing attackers to escalate privileges, steal credentials, and gain persistent access to the network.
Uncovering the Attack Methodology
Hunt.io researchers first identified an open directory linked to the attack on June 3, 2026. Located at 92.63.180[.]133:8888 and hosted on Bangmod Enterprise infrastructure, the server contained an array of tools and scripts. These included FortiGate exploitation scripts, SSH brute-force utilities, and database credential harvesters, providing a comprehensive view of the hacker’s operations.
Evidence pointed to the attackers exploiting a FortiGate 60F SSL-VPN vulnerability, specifically CVE-2024-21762, which was added to CISA’s Known Exploited Vulnerabilities catalog earlier in the year. This vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary commands through crafted HTTP requests.
Detailed Analysis of the Exploitation
The attackers used controlled crashes and malformed HTTP requests to determine the vulnerability of the FortiGate appliance. The final exploit involved advanced techniques, such as heap spraying and return-oriented programming, to establish a reverse shell to their server.
Further analysis revealed the use of MeshCentral as a remote management tool, installed to maintain persistent access within the network. The MeshCentral configuration directed infected machines to connect over port 443, with several systems reportedly under active administrative control during the attack.
Implications and Recommendations
The attackers demonstrated extensive knowledge of the 3BB network, employing various scripts to probe for vulnerabilities and escalate privileges on compromised Linux servers. They also targeted other systems, including a CodeIgniter-based sales portal and a Pentaho server, using known vulnerabilities like Dirty COW and Ghostcat.
Organizations potentially affected by similar threats should investigate unusual MeshCentral agent activity, connections to suspicious domains, and unexplained gaps in security logs. Immediate actions include rotating sensitive credentials and preserving forensic evidence to counteract the attack’s anti-forensic measures.
Fortinet has identified several FortiOS versions vulnerable to this exploit and recommends upgrading to a supported fixed release. Disabling SSL-VPN entirely can serve as a temporary measure if patching is not immediately possible.
The breach highlights the critical importance of promptly addressing known vulnerabilities and implementing comprehensive security measures to safeguard network infrastructure.
