Thai Broadband Provider Hacked via Fortinet Vulnerability
Attackers gained access to Thai provider 3BB's systems via CVE-2024-21762 in FortiGate SSL-VPN and reconnaissance against F5 BIG-IP. The attack was discovered after hackers left 298 files with tools in an open directory on infrastructure in Thailand.
- Used RCE vulnerability CVE-2024-21762 in FortiGate SSL-VPN
- Also checked CVE-2018-13379, CVE-2022-42475, and CVE-2023-27997
- 298 files in 30 subdirectories found in open directory
- MeshCentral used as C&C platform for persistence
Read next
Security