Thai Broadband Provider Hacked via Fortinet Vulnerability
A Thai broadband provider, 3BB, was targeted by a threat actor who exploited vulnerabilities in Fortinet and F5 products to gain access to their systems. The attackers left behind a comprehensive arsenal of tools, including exploitation scripts, backdoor installers, and a MeshCentral instance, demonstrating a sophisticated and persistent intrusion campaign.
A Thai broadband provider, 3BB (Triple T Broadband), has been compromised by a threat actor who leveraged vulnerabilities in Fortinet and F5 products to gain unauthorized access to their systems. Hunt.io discovered a staged intrusion environment containing a wide range of tools designed for reconnaissance, exploitation, and persistent remote access. The attack began with careful fingerprinting of a FortiGate SSL-VPN endpoint using eight shell scripts to identify firmware versions and probe for vulnerabilities, ultimately deploying an exploit targeting CVE-2024-21762 for remote code execution (RCE).
Simultaneously, the attackers conducted reconnaissance against 3BB’s F5 BIG-IP instance, exploiting multiple vulnerabilities including CVE-2021-22986, CVE-2022-1388, and CVE-2023-46747, as well as targeting 3BB’s internal sales agent portal. Following initial access, the attackers attempted to escalate privileges on multiple Linux systems using PwnKit and Dirty COW exploits, alongside a dedicated SUID backdoor installer.
The attackers then utilized various scripts for host discovery, remote access, and credential harvesting to move laterally across 3BB’s internal environment, attempting to extract SSH keys, PHP configurations, database credentials, SNMP community strings, and Radius authentication data, and to perform passwordless MySQL authentication against internal databases. They deployed PHP web shells and injected SSH keys, and modified database privileges to facilitate persistence and lateral movement.
Finally, the attackers executed a script to remove artifacts associated with vulnerability exploitation and backdoor deployment, including PHP web shells, MeshCentral deployment scripts, and system logs, ensuring continued remote access and persistence. The script verified that persistence mechanisms remained operational, confirming the MeshCentral service was still running. This indicates a deliberate effort to conceal the intrusion while maintaining remote control.