Fortinet Vulnerability Exploited in Thai Broadband Provider Hack
Thai broadband provider 3BB suffered a cyberattack exploiting vulnerabilities in Fortinet and F5 products, according to a report by Hunt.io.
Breach Details
The breach was uncovered when the attackers left their toolkit in an accessible directory hosted on infrastructure in Thailand. The repository contained 298 files across 30 subdirectories, including exploitation scripts, brute-force tools, privilege escalation mechanisms, credential extraction utilities, a machine inventory, and a MeshCentral instance configured as a persistent backdoor. The files were organized under operational categories such as Exploit, Victim, Config, and History, indicating an active staging environment. The tools were specifically developed for 3BB, a major fixed-line broadband service in Thailand with millions of users, and its predecessor Jasmine.
Attack Methods
Initial access was achieved by analyzing a FortiGate SSL-VPN endpoint using eight custom shell scripts. These scripts identified the firmware version, tested for vulnerabilities, and executed exploits. The attackers targeted known flaws including
- CVE-2018-13379
- CVE-2022-42475
- CVE-2023-27997
- CVE-2024-21762
. After confirming the firmware version, they deployed an exploit for CVE-2024-21762 to achieve remote code execution. Concurrently, the threat actor scanned
