Executive Summary
An open directory staging server hosted on Bangmod Enterprise infrastructure has revealed an extensive intrusion operation targeting Thai broadband providers 3BB (Triple T Broadband) and Jasmine International. The threat actor, utilizing the MeshCentral group name 'TH-3BB', successfully exploited CVE-2024-21762 in FortiGate SSL-VPN appliances to gain initial access, subsequently establishing a deep foothold within the internal network.
The attack chain involved sophisticated reconnaissance of FortiOS firmware to adapt ROP gadgets, followed by lateral movement targeting RADIUS authentication databases (radius_corp, radiusinfo) to harvest subscriber credentials. The actor utilized a diverse toolkit for post-exploitation, including PwnKit and Dirty COW for privilege escalation, and Ghostcat for targeting internal Pentaho servers.
This activity represents a high-risk threat to telecommunications infrastructure in Thailand. The discovery of active session cookies and MeshCentral device inventories confirms that multiple internal systems were successfully compromised and under active administrative control by the attacker. Organizations in the region should immediately audit for MeshCentral agents and unpatched edge gateway vulnerabilities.
Key Details
Threat Name
CVE-2024-21762
Affects
FortiGate 60F, FortiOS 7.2.0-7.2.6, F5 BIG-IP, Apache Tomcat, Pentaho BI server, polkit pkexec, Linux systems, Linux Kernel, FortiGate SSL-VPN, FortiOS administrative interface
Adversary
TH-3BB
Malware/Tools
MeshCentral, PwnKit, Ghostcat, Dirty COW, XORtigate
