www.securityweek.com 15 Sept 2026, 13:33 UTC

Attackers Exploited Fortinet and F5 Flaws to Target Thai ISP 3BB

Attackers Exploited Fortinet and F5 Flaws to Target Thai ISP 3BB

THREAT actors targeted Thai broadband provider 3BB, also known as Triple T Broadband, by exploiting vulnerabilities in Fortinet and F5 products, according to cybersecurity firm Hunt.io. The intrusion was uncovered after the attackers left their tools in an openly accessible directory hosted on infrastructure in Thailand.

The directory contained 298 files in 30 subdirectories, including exploit scripts, brute-force and privilege-escalation tools, credential-stealing scripts, records of compromised machines and a MeshCentral agent configured to provide persistent remote access. Hunt.io said the tools appeared to have been tailored for 3BB and Jasmine, the company that previously owned Triple T Broadband.

The attackers fingerprinted a FortiGate SSL-VPN appliance with eight shell scripts, checking its firmware and probing for CVE-2018-13379, CVE-2022-42475, CVE-2023-27997 and CVE-2024-21762. They then used an exploit for CVE-2024-21762 to obtain remote code execution. They also examined an F5 BIG-IP system and an internal sales portal for CVE-2021-22986, CVE-2022-1388 and CVE-2023-46747.

After gaining access, the attackers attempted Linux privilege escalation using PwnKit and Dirty COW exploits, installed a SUID backdoor and deployed MeshCentral for continued control.

Hunt.io said the intruders sought SSH keys, PHP and database credentials, SNMP community strings and Radius authentication data, while using web shells, injected SSH keys and altered database privileges to maintain access and move laterally. A later cleanup script removed exploitation artefacts, web shells, deployment scripts and logs, but checked that the hidden SUID binary and MeshCentral service remained active, indicating concealment rather than full remediation.

View full article

Article by CyberSIXT