Thai Broadband Provider Compromised via FortiGate and MeshCentral
Score: 9/10

Thai Broadband Provider Compromised via FortiGate and MeshCentral

A threat actor designated TH-3BB targeted Thai ISP 3BB and Jasmine International using CVE-2024-21762 for initial access and MeshCentral for persistent command-and-control.

Executive Summary

An open directory staging server hosted on Bangmod Enterprise infrastructure has revealed an extensive intrusion operation targeting Thai broadband providers 3BB (Triple T Broadband) and Jasmine International. The threat actor, utilizing the MeshCentral group name 'TH-3BB', successfully exploited CVE-2024-21762 in FortiGate SSL-VPN appliances to gain initial access, subsequently establishing a deep foothold within the internal network.

The attack chain involved sophisticated reconnaissance of FortiOS firmware to adapt ROP gadgets, followed by lateral movement targeting RADIUS authentication databases (radius_corp, radiusinfo) to harvest subscriber credentials. The actor utilized a diverse toolkit for post-exploitation, including PwnKit and Dirty COW for privilege escalation, and Ghostcat for targeting internal Pentaho servers.

This activity represents a high-risk threat to telecommunications infrastructure in Thailand. The discovery of active session cookies and MeshCentral device inventories confirms that multiple internal systems were successfully compromised and under active administrative control by the attacker. Organizations in the region should immediately audit for MeshCentral agents and unpatched edge gateway vulnerabilities.

Key Details

Threat Name

CVE-2024-21762

Affects

FortiGate 60F, FortiOS 7.2.0-7.2.6, F5 BIG-IP, Apache Tomcat, Pentaho BI server, polkit pkexec, Linux systems, Linux Kernel, FortiGate SSL-VPN, FortiOS administrative interface

Adversary

TH-3BB

Malware/Tools

MeshCentral, PwnKit, Ghostcat, Dirty COW, XORtigate

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure10
Technical Depth9

Sources