An attacker breached the network of Thailand's largest broadband provider, 3BB, and maintained remote access to internal systems using a legitimate management tool called MeshCentral This article explores examining server attacker. . Threat intelligence firm Hunt.io discovered the intrusion by examining a server the attacker had left open on the internet, which contained their own tools and a list of machines already under their control.
The tools present on it were executed from within 3BB's own network, and one recovered file indicated the attacker gained full administrative control, known as root, over an internal server. They deployed scripts that compromised 55 internal computers via SSH, probed the 3BB's internal sales portal at agent.3bb.co[. ]th, and searched for stored passwords, database logins, and SSH keys on compromised machines.
The server possessed a comprehensive toolkit designed for a 3BB FortiGate SSL-VPN gateway, the remote-access server at mail.3bb.co[. ]th, including a complete exploit for CVE-2024-21762, a significant 2024 Fortinet vulnerability that allows attackers to execute code on the device without requiring login. ### What Defenders Should Do The recovered toolkit provides a detailed guide for organizations running similar edge devices and authentication systems: Verify that FortiGate SSL-VPN appliances are addressed in the CVE-2024-21762 patch.
Search for sneaky ways back, like unexpected SUID files, web shells, altered SSH keys, and newly added remote management software. Persistence paths: /usr/local/bin/.rc, a hidden backdoor, and /usr/local/mesh_services/meshagent/.












