Misconfigured Server Exposes Massive Thai ISP Intrusion

FortiGate device conceptual image alongside MeshCentral control panel elements

A staggering misconfiguration within an attacker’s own offensive infrastructure fortuitously exposed nearly the entire exploitation chain orchestrated against a prominent Thai internet service provider. Hunt.io analysts discovered an unprotected, openly accessible server maintained by the malicious actor. This repository contained exactly 298 sensitive files meticulously organized across 30 directories. These files provided irrefutable evidence of a sophisticated intrusion into the internal network of 3BB, a major Thai telecommunications operator. The evidence detailed the establishment of persistent footholds on internal machines and a highly targeted campaign designed to harvest subscriber credentials.

Exploiting FortiGate CVE-2024-21762

Hunt.io directly linked this elaborate operation to a specific FortiGate 60F appliance that actively managed the SSL-VPN infrastructure for 3BB. The attacker’s methodology was precise: they initially identified the exact hardware model and the running firmware version. Subsequently, they ruthlessly probed the gateway for the presence of CVE-2024-21762. This catastrophic out-of-bounds write vulnerability boasts a critical 9.8 score on the CVSS 3.1 scale. Critically, it allows an unauthenticated remote attacker to execute arbitrary code simply by transmitting a specially crafted HTTP request directly to the vulnerable SSL-VPN service.

The inadvertently exposed dataset preserved the entire, functional exploitation chain in remarkable detail. Specialized scripts expertly groomed the device’s memory, meticulously initiated a complex Return-Oriented Programming (ROP) chain, and successfully established a covert reverse connection back to the attacker’s command server. To ensure flawless execution against the specific FortiGate 60F target, the attacker audaciously attempted to acquire the precise FortiOS 7.2.5 firmware image by exploiting the target device’s unique serial number during unauthorized requests made directly to Fortinet’s official infrastructure.

Internal Network Compromise and MeshCentral Deployment

Following the successful perimeter breach, the attack swiftly migrated deep into the internal network. One specific file unequivocally documented the execution of commands with elevated root privileges directly on a critical 3BB Linux server. Furthermore, the repository contained bespoke tools explicitly engineered for privilege escalation, the surreptitious installation of a concealed SUID backdoor, and the systematic theft of sensitive SSH keys, application configurations, and plaintext passwords.

To guarantee long-term, undetectable control over the compromised environment, the adversary cleverly selected MeshCentral. This legitimate, open-source remote administration tool provided the perfect cover. The agent configuration explicitly referenced a designated “TH-3BB” group and an external command and control server. Alarmingly, an export of managed devices revealed several active internal machines running MeshCentral agents with full root privileges. Utilizing this specific channel brilliantly masquerades malicious activity as routine administrative traffic, making it exceptionally difficult to detect amidst legitimate network operations.

Expanding Access and Targeting RADIUS Infrastructure

Simultaneously, the attacker proactively established redundant entry points and aggressively expanded their unauthorized access. Custom MySQL scripts were designed to seamlessly write PHP web shells directly into web server directories, covertly inject unauthorized SSH keys, and maliciously alter permissions within critical databases. Auxiliary utilities tirelessly executed password spraying attacks against more than 55 internal nodes, aggressively seeking unauthorized access to FTP, MySQL, MongoDB, and Redis services originating directly from within the presumably trusted network segment.

The RADIUS infrastructure, which the operator utilizes to authenticate legitimate subscriber credentials, emerged as a distinct and highly prized target. The exposed toolkit contained a specialized script engineered specifically to extract sensitive data from the radius_corp, radiusinfo, and job_radius databases, utilizing a hardcoded MySQL root password. While Hunt.io could not definitively confirm the mass exfiltration of subscriber data, the evidence undeniably proves the attacker’s intent, even if the actual leakage of millions of client records remains unverified.

Covering Tracks and Remediation Advice

The sophisticated attacker had meticulously prepared a comprehensive strategy for erasing their digital footprints. A script named cleanup_target.sh was designed to systematically delete system logs, command histories, privilege escalation components, and deployed web shells. However, it intentionally preserved the MeshCentral installation and the concealed SUID backdoor. This devious tactic allowed the attacker to obscure their previous malicious actions while simultaneously maintaining persistent, unauthorized access.

Hunt.io initially discovered the exposed working directory on June 3, 2026, while the malicious operation remained actively ongoing. They subsequently published a detailed report on the Thai broadband FortiGate SSL-VPN intrusion on September 14. Prior to public disclosure, the company responsibly notified the affected parties and the relevant CERT authorities, although they did not disclose the specifics of any subsequent responsive actions. Security experts strongly advise all FortiGate administrators to immediately verify firmware versions, diligently search for unauthorized MeshCentral agents, and proactively rotate all privileged credentials, VPN certificates, and cryptographic keys.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply