Executive Summary
An unidentified threat actor successfully infiltrated the network of 3BB, a major Thai broadband provider, maintaining long-term access via the legitimate remote management tool MeshCentral. The intrusion was discovered when Hunt.io identified an exposed server belonging to the attacker that contained an active toolkit, device lists, and evidence of administrative (root) access to internal systems. While the initial entry vector is not fully confirmed, the attacker's toolkit included a functional exploit for CVE-2024-21762, a critical FortiOS SSL-VPN vulnerability.
The attacker's primary objectives appeared to be credential harvesting and lateral movement. They targeted RADIUS databases containing subscriber credentials, internal sales portals, and shared infrastructure with the Jasmine network. A notable aspect of the operation was the use of a custom cleanup script designed to erase evidence of the attacker's presence while specifically leaving the MeshCentral agent active to ensure persistent access.
This incident highlights the ongoing risk posed by unpatched edge devices and the increasing trend of 'living off the land' by abusing legitimate remote management software. Organizations in the telecommunications and critical infrastructure sectors should prioritize patching Fortinet appliances and auditing their environments for unauthorized remote access tools.
