oxhak on Nostr: Attackers compromised 3BB, one of Thailand’s largest fixed-line broadband ...
Attackers compromised 3BB, one of Thailand’s largest fixed-line broadband providers, by targeting Fortinet FortiGate SSL-VPN and F5 BIG-IP systems. Hunt.io found an exposed directory containing 298 files in 30 subdirectories, including scripts for firmware fingerprinting, exploitation, brute force, privilege escalation, credential harvesting and persistence. The actor used a FortiGate exploit for remote code execution and probed multiple F5 flaws.
After gaining access, the attackers deployed MeshCentral as a persistent backdoor, moved laterally and attempted to extract SSH keys, PHP and database credentials, SNMP strings and RADIUS data. They installed web shells, altered database privileges and used cleanup scripts to remove evidence while checking that persistence remained active. The case shows how exposed network appliances can enable stealthy credential theft and long-term access at a provider serving millions of users.
https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/Published at
2026-09-15 14:05:53 UTCEvent JSON
{
"id": "d7a554858e9c4f9cc4e66abf33411e38ec60b3cb5ba31459a2cf7f0bf45105db",
"pubkey": "81b26cb98224311ea520a9042bf9c7cc78d2725d0a99f9797afd9a8a35970aaa",
"created_at": 1789481153,
"kind": 1,
"tags": [],
"content": "Attackers compromised 3BB, one of Thailand’s largest fixed-line broadband providers, by targeting Fortinet FortiGate SSL-VPN and F5 BIG-IP systems. Hunt.io found an exposed directory containing 298 files in 30 subdirectories, including scripts for firmware fingerprinting, exploitation, brute force, privilege escalation, credential harvesting and persistence. The actor used a FortiGate exploit for remote code execution and probed multiple F5 flaws.\n\nAfter gaining access, the attackers deployed MeshCentral as a persistent backdoor, moved laterally and attempted to extract SSH keys, PHP and database credentials, SNMP strings and RADIUS data. They installed web shells, altered database privileges and used cleanup scripts to remove evidence while checking that persistence remained active. The case shows how exposed network appliances can enable stealthy credential theft and long-term access at a provider serving millions of users.\n\nhttps://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/",
"sig": "1360d15f37499b89d70c5b63746b53b42b576da36b7b5916df3d3c803cff9e4554a81762685397d6fcd02817147877bf4937a5a8c652b4dd0b09ecc3c7869d33"
}