---
url: "https://www.xcademia.com/news/thai-broadband-provider-hit-in-fortigate-attack-with-meshcentral-persistence"
title: Thai Broadband Provider Hit in FortiGate Attack With MeshCentral Persistence
description: "Hunt.io uncovered a 3BB intrusion using FortiGate CVE-2024-21762, internal reconnaissance, credential attacks and MeshCentral persistence."
publishedAt: "2026-09-15T10:32:15.161+00:00"
updatedAt: "2026-09-15T12:11:29.355283+00:00"
type: news
category: cybersecurity
source_name: "Hunt.io - Threat Research"
source_url: "https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion"
tags:
  - "#Cybersecurity"
  - "#FortiGate"
  - "#ThreatIntelligence"
  - "#CyberAttack"
  - "#MeshCentral"
  - "#RansomwareAndIntrusion"
  - "#NetworkSecurity"
  - "#CVE202421762"
---

# Thai Broadband Provider Hit in FortiGate Attack With MeshCentral Persistence

> Hunt.io uncovered an active intrusion targeting Thailand's 3BB broadband infrastructure, combining FortiGate SSL-VPN exploitation, credential attacks, internal reconnaissance and MeshCentral persistence.

Source: **Hunt.io - Threat Research** · 15 September 2026

## Thai Broadband Provider Targeted Through FortiGate SSL-VPN

A threat actor targeted Thailand's 3BB broadband infrastructure using a combination of FortiGate SSL-VPN exploitation, credential attacks, internal reconnaissance and persistent remote access.

The activity was uncovered by Hunt.io after its AttackCapture platform identified an exposed directory on a server in Thailand. The directory contained **298 files across 30 subdirectories, totalling 19 MB**, including exploitation scripts, credential-harvesting tools, privilege-escalation utilities, persistence tooling and information about compromised systems. Hunt.io said the directory was first captured on **3 June 2026**.

The discovery provided researchers with an unusually detailed view of an intrusion operation targeting **3BB, also known as Triple T Broadband**.

Hunt.io's disclosure said it notified affected parties and the relevant CERT before publication under a TLP:AMBER advance copy. The notification statement does not establish what actions affected organisations subsequently took.

## 
The Attack Started With FortiGate Reconnaissance

The recovered tooling shows that the actor did not immediately rely on a single exploit.

Instead, the attacker first fingerprinted a **FortiGate 60F SSL-VPN endpoint** associated with 3BB. Scripts named `forti1.sh` through `forti8.sh` were used to gather information about the exposed appliance and determine its FortiOS version.

The reconnaissance included HTTP response analysis, SSL-VPN page retrieval and queries against FortiGate endpoints. The actor also tested the appliance against several known vulnerabilities, including:

- CVE-2022-42475
- CVE-2023-27997
- CVE-2018-13379
- CVE-2024-21762

The recovered scripts indicate that the actor eventually focused on **CVE-2024-21762**, a FortiOS vulnerability affecting the SSL-VPN component.

Hunt.io's analysis states that the recovered material identified the target as a FortiGate 60F running a firmware build associated with the vulnerable FortiOS 7.2.0 through 7.2.6 range.

The attacker also attempted targeted credential validation against the SSL-VPN login endpoint using organisation-specific password material and common VPN usernames. Hunt.io noted that the source of the organisation-specific credential knowledge was not confirmed.

![info-1](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789468204801-info1--74-.webp)

## 
CVE-2024-21762 Was Used to Establish Remote Code Execution

Once the actor determined that the FortiGate appliance was vulnerable, the recovered toolkit contained a structured exploitation process.

Hunt.io describes several stages of vulnerability validation before the actor moved to full exploitation. The toolkit included proof-of-concept and verification scripts designed to determine whether the SSL-VPN service behaved like a vulnerable deployment.

The final exploitation tooling then used a multi-stage process involving memory manipulation and a return-oriented programming chain to obtain remote code execution. According to Hunt.io, the resulting reverse shell connected back to infrastructure hosted on the same server where the exposed operational directory was found.

The exposed directory therefore provided evidence connecting the attacker's exploitation infrastructure with the compromised environment.

The actor also attempted to obtain the target FortiOS firmware image. Recovered scripts referenced the FortiGate device's serial number and attempted to retrieve the corresponding firmware, apparently to support exploitation preparation and ROP adaptation.

## 
The Campaign Extended Beyond the VPN Gateway

The FortiGate intrusion was only one component of the operation.

Hunt.io also identified extensive reconnaissance against **agent.3bb.co[.]th**, described as an internal sales agent portal running CodeIgniter 2 behind an F5 BIG-IP load balancer.

The recovered `deep1.sh` through `deep11.sh` scripts assessed several aspects of the application and its supporting infrastructure.

The activity included testing for:

- Authentication weaknesses
- Session manipulation
- File upload issues
- SQL injection
- Path traversal
- HTTP request smuggling
- Cookie-based authorisation weaknesses
- Additional internal subdomains
- F5 BIG-IP exposure

One recovered response file contained the HTML response from an authenticated internal application page. Hunt.io said this confirmed that the actor had successfully accessed internal portal functionality during the reconnaissance phase.

![info-2](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789468225018-info2--76-.webp)

## 
F5 BIG-IP Systems Were Also Probed

The actor separately examined an F5 BIG-IP appliance associated with the environment.

Recovered scripts tested for several known vulnerabilities, including **CVE-2021-22986, CVE-2022-1388 and CVE-2023-46747**.

The actor also analysed an F5 persistence cookie recovered from the application environment. Hunt.io said the activity appeared aimed at understanding backend infrastructure and potential ways around intermediary security controls.

This illustrates that the operation was not limited to exploiting a single vulnerable edge device. Once the actor gained visibility into the environment, the recovered tooling shows continued attempts to identify alternative routes into internal systems.

## 
Privilege Escalation and Linux Host Compromise

The recovered toolkit contained several Linux privilege-escalation mechanisms.

These included tooling associated with:

- PwnKit
- Dirty COW
- SUID-based persistence

Hunt.io also identified tooling for exploiting **CVE-2020-1938, known as Ghostcat**, against an internal Pentaho BI server.

The recovered evidence included a file recording root-level command execution on an internal Linux application server, which Hunt.io interpreted as evidence of successful compromise.

This stage significantly increased the potential impact of the intrusion. Initial access through an internet-facing appliance had developed into privileged access to internal Linux infrastructure.

## 
MeshCentral Became the Persistence Mechanism

One of the most significant findings was the use of **MeshCentral** for persistent remote access.

MeshCentral is legitimate remote-management software, but in this case Hunt.io found evidence that it had been configured as part of the intrusion.

The recovered `meshagent.msh` configuration placed systems into a group named **TH-3BB** and pointed agents towards `www.ayuthayatech[.]com` as the management server. The configuration used WebSocket communications over port 443.

Hunt.io's analysis found that the domain had been registered in January 2026 and that its nameservers later moved to Cloudflare.

The researchers assessed the recently registered domain, its role as the MeshCentral management host and its infrastructure changes as consistent with purpose-built command-and-control infrastructure.

The recovered `devices.json` file was particularly significant.

It contained information about enrolled systems, including operating systems, addresses, connection states and privilege levels. Multiple systems were shown as actively connected, with agents running with root privileges at the time of the export.

Hunt.io also found a second MeshCentral group associated with another organisation. However, the researchers explicitly noted that this alone does **not confirm that the additional organisation was compromised**.

![info-3](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789468246099-info3--74-.webp)

## 
Internal Credential Access and Lateral Movement

After establishing persistence, the actor expanded activity across the internal environment.

The recovered `brute.sh`, `brute2.sh` and `brute3.sh` scripts performed SSH password spraying against **more than 55 internal hosts**. The scripts used both common and organisation-specific credentials.

Other tools targeted:

- SSH keys
- PHP configuration files
- Database credentials
- SNMP community strings
- Shell history
- MySQL databases
- FTP services

A dedicated credential-hunting script searched compromised systems for sensitive authentication material.

Another script targeted RADIUS databases including `radius_corp`, `radiusinfo` and `job_radius`. Hunt.io said the activity indicated an effort to obtain authentication information connected with the organisation's RADIUS infrastructure.

The recovered tooling also attempted to abuse MySQL functionality to read sensitive files, deploy PHP web shells and inject SSH keys.

## 
RADIUS Infrastructure Was a Major Target

The focus on RADIUS infrastructure is particularly important because the recovered scripts were not limited to ordinary server credentials.

Hunt.io said the attacker targeted databases associated with subscriber authentication and described access to RADIUS data as part of the apparent objective of obtaining subscriber credentials.

The investigation also uncovered an OpenVPN configuration associated with the Jasmine and Triple T Broadband environment. The configuration contained a certificate and private key issued to a client identified as `bbclient`.

Hunt.io said the certificate **would provide VPN access if it were still valid**, but the investigation does not establish its current validity or whether it was actually used successfully.

Additional session artefacts associated with Jasmine-branded systems suggested that activity extended beyond 3BB alone.

## 
The Attack Also Targeted Jasmine-Linked Infrastructure

3BB and Jasmine are connected through their corporate and infrastructure history, and Hunt.io found artefacts indicating activity involving both environments.

Recovered files included session information associated with `ccs.jasmine.com` and systems within the related network range.

Hunt.io therefore assessed the operation as broader than a single isolated 3BB intrusion. However, the evidence should be interpreted carefully: the presence of artefacts does not by itself establish that every referenced system was successfully compromised.

## 
Cleanup Was Designed to Preserve Access

The final stage of the recovered toolkit focused on anti-forensics.

The `cleanup_target.sh` script was designed to remove exploitation artefacts, delete web shells and clear system logs and shell histories.

But the cleanup process did not simply remove everything.

According to Hunt.io, the script deliberately checked that persistence mechanisms remained operational, including the hidden SUID binary and the MeshCentral service.

This combination of evidence removal and persistence is significant because it shows an effort to reduce the forensic footprint while maintaining remote access.

For defenders, this also means that the absence of obvious exploitation files after an incident should not automatically be interpreted as evidence that the attacker has left the environment.

## 
What Organisations Should Take From the Incident

Hunt.io recommends that organisations operating FortiGate SSL-VPN appliances and similar infrastructure take several defensive measures.

The first priority is to **verify exposure to CVE-2024-21762** and ensure FortiGate devices are running supported and fully patched firmware.

Security teams should also review VPN infrastructure for:

- Unexpected accounts
- Abnormal authentication activity
- Unauthorised configuration changes
- Suspicious administrative activity

MeshCentral deployments deserve particular attention. Organisations should investigate unexpected agents, unauthorised enrolments, unusual WebSocket connections and communications with unapproved management infrastructure.

Where compromise is suspected, Hunt.io recommends rotating potentially exposed privileged credentials, including SSH keys, database credentials, VPN certificates, RADIUS credentials and application secrets.

Security teams should also hunt for hidden SUID binaries, web shells, modified SSH keys, unauthorised scheduled tasks and newly installed remote-management software.

Finally, forensic evidence should be preserved before remediation where possible because the recovered cleanup tooling demonstrates that attackers may attempt to remove evidence of their activity.

## 
Why This Incident Matters

The investigation highlights a broader security problem for organisations that depend heavily on internet-facing infrastructure.

The initial entry point was an exposed VPN appliance, but the subsequent activity crossed several security layers: application infrastructure, F5 BIG-IP systems, Linux servers, databases, authentication systems and remote-management software.

The incident therefore demonstrates how an exposed edge device can become the starting point for a much broader intrusion when attackers are able to establish internal access and persistence.

It also highlights the risk of legitimate administration tools being repurposed for malicious access. MeshCentral itself is not inherently malicious. In this investigation, however, it was configured as a persistence and remote-access mechanism.

For enterprises, the practical lesson is that security monitoring needs to extend beyond traditional malware detection. Unexpected remote-management agents, unusual authentication patterns, suspicious VPN activity and changes to privileged access can all provide important signals.

## 
Hunt.io's Findings in Context

The investigation is particularly notable because the exposed directory provided a view into multiple stages of the operation rather than a single isolated indicator.

Hunt.io recovered evidence relating to:

1. Internet-facing FortiGate reconnaissance
2. Vulnerability validation
3. CVE-2024-21762 exploitation
4. Remote code execution
5. Internal web application reconnaissance
6. F5 BIG-IP vulnerability probing
7. Linux privilege escalation
8. Credential harvesting
9. RADIUS database targeting
10. SSH-based lateral movement
11. MeshCentral persistence
12. Anti-forensic cleanup

The combination gives defenders a more complete picture of how an intrusion can progress from an exposed perimeter device to internal systems.

## 
Key Defensive Priorities

**For security teams, the immediate priorities are:**

- Check FortiGate appliances for exposure to CVE-2024-21762.
- Ensure internet-facing security appliances are fully patched and supported.
- Review SSL-VPN authentication logs for unusual activity.
- Investigate unexpected MeshCentral agents and management servers.
- Review privileged SSH keys and credentials.
- Audit RADIUS databases and authentication infrastructure.
- Search for web shells and hidden SUID binaries.
- Examine unexpected MySQL file operations.
- Review internal SSH password-spraying activity.
- Preserve forensic evidence before removing suspected attacker infrastructure.

The full IOC list published by Hunt.io includes network indicators, domains, filenames, persistence paths, cookies and other artefacts that defenders can use for threat hunting.

## 
Conclusion

Hunt.io's investigation exposes a detailed intrusion targeting Thailand's 3BB broadband infrastructure.

The operation began with reconnaissance of a FortiGate SSL-VPN appliance and exploitation of **CVE-2024-21762**, but the recovered evidence shows that the actor's objectives extended much further. The toolkit included internal application reconnaissance, F5 BIG-IP vulnerability testing, Linux privilege escalation, credential harvesting, RADIUS database targeting and SSH-based lateral movement.

The use of **MeshCentral** as persistent remote access was particularly significant. Multiple systems were shown as actively connected to the attacker's management infrastructure, with some agents operating with root privileges.

The investigation also shows the importance of monitoring both edge infrastructure and internal authentication systems. A vulnerability at the perimeter can become considerably more serious when attackers are able to establish persistence and move through the internal environment.

For organisations operating FortiGate appliances, the most immediate action is to verify exposure to **CVE-2024-21762**, ensure supported firmware is deployed and investigate the published indicators for evidence of compromise.

## Original source

https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion

## Tags

`#Cybersecurity` · `#FortiGate` · `#ThreatIntelligence` · `#CyberAttack` · `#MeshCentral` · `#RansomwareAndIntrusion` · `#NetworkSecurity` · `#CVE202421762`

---

## About this content

This Markdown news article is the citation-grade twin of [Thai Broadband Provider Hit in FortiGate Attack With MeshCentral Persistence](https://www.xcademia.com/news/thai-broadband-provider-hit-in-fortigate-attack-with-meshcentral-persistence). It is published by **Xcademia** (UK Companies House 12322710) and is available for AI search engines and large language models to index, summarise, and cite.

When citing or quoting, please attribute *Xcademia* and link back to the source URL above.

- Source: https://www.xcademia.com/news/thai-broadband-provider-hit-in-fortigate-attack-with-meshcentral-persistence
- Publisher: Xcademia — https://www.xcademia.com
- Catalogue index: https://www.xcademia.com/llms-full.txt
