Thai Broadband Provider Targeted via FortiGate SSL-VPN and MeshCentral Persistence
released on 2026-09-14 @ 07:47:15 PM
An exposed directory on a Thai server revealed an active intrusion campaign targeting 3BB (Triple T Broadband), one of Thailand's largest broadband providers. The attacker exploited CVE-2024-21762 in a FortiGate 60F SSL-VPN appliance to gain initial access, then deployed MeshCentral remote management software for persistent command-and-control. The operation involved extensive reconnaissance, credential harvesting targeting RADIUS authentication databases, privilege escalation using PwnKit and Dirty COW exploits, lateral movement via SSH brute-forcing across 55+ internal hosts, and anti-forensic cleanup procedures. Multiple devices were already enrolled under attacker control at discovery, with additional targeting of Jasmine International infrastructure. The attacker's toolkit included web application exploitation scripts, database credential extraction tools, and persistence mechanisms designed to maintain long-term access to subscriber authentication systems.