3BB Hacked via Fortinet Vulnerability, Attackers Leave Arsenal Exposed
Summary
A cyberattack on the Thai broadband provider 3BB has been linked to vulnerabilities in Fortinet and F5 products, as reported by Hunt.io. Attackers exploited multiple known vulnerabilities, particularly CVE-2024-21762, to gain initial access to 3BB's systems, which serve millions of users in Thailand. The intrusion was uncovered when a directory containing 298 files related to exploitation tools and credential harvesting scripts was found exposed on servers in Thailand. Notably, these attacks utilize legitimate platforms like MeshCentral for persistent remote access, allowing the hackers to maintain control over compromised systems after gaining entry.
Analysis
3BB: 3BB, operating as Triple T Broadband, is a leading provider of fixed-line broadband services in Thailand. The company serves as the primary victim in a recent intrusion where threat actors exploited multiple Fortinet and F5 vulnerabilities to access its systems. Hunt.io's analysis of the attack specifically targeted tools and reconnaissance tailored to 3BB's infrastructure. Hunt.io: Hunt.io is a cybersecurity firm focused on threat intelligence, infrastructure analysis, and exposing attacker tooling through open directories and network observations. It published the detailed September 2026 report uncovering the 3BB intrusion staging environment and the specific exploitation scripts used. The firm regularly discloses findings from captured attack artifacts to affected parties and the security community. Jasmine: Jasmine International is a Thai telecommunications and media holding company that previously owned Triple T Broadband, the operator behind 3BB. Following the divestment of its broadband business, Jasmine has redirected its focus to media, content delivery, and technology solutions segments. The breach report references its prior ownership connection to the targeted provider. Threat Discovery: Publicly exposed attacker staging directories on compromised or controlled servers frequently reveal detailed operational toolkits, target inventories, and cleanup routines used in sophisticated intrusions. Persistence Methods: Attackers are deploying legitimate remote administration platforms such as MeshCentral to maintain persistent command-and-control access following successful network compromise. Vulnerability Exploitation: Threat actors continue to actively exploit known remote code execution flaws in Fortinet FortiGate SSL-VPN appliances, including CVE-2024-21762, for initial access to enterprise and infrastructure targets.
Categories
cryptotech
Related sources
- https://db.gcve.eu/vuln/cve-2024-21762
- https://investor.jasmine.com/storage/downloads/shareholders-meetings/agm2026/20260511-jas-agm2026-minutes-en.pdf
- https://th.wikipedia.org/wiki/%E0%B8%88%E0%B8%B1%E0%B8%AA%E0%B8%A1%E0%B8%B4%E0%B8%99_%E0%B8%AD%E0%B8%B4%E0%B8%99%E0%B9%80%E0%B8%95%E0%B8%AD%E0%B8%A3%E0%B9%8C%E0%B9%80%E0%B8%99%E0%B8%8A%E0%B8%B1%E0%B9%88%E0%B8%99%E0%B9%81%E0%B8%99%E0%B8%A5
- https://tracxn.com/d/companies/3bb/__jxgLo-jsldbQeR-7bTM4jsdPcBBYBDSTZFCj3CC2uUs
- https://ground.news/article/3bb-attacker-used-meshcentral-backdoor-for-root-access-targeted-subscriber-credentials
- https://www.thansettakij.com/technology/668839
- https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/
- https://www.ct.nl/app/uploads/2026/02/Cyber-Trend-Report-Hunt-Hackett-2026.pdf
- https://safeguard.sh/resources/blog/fortios-cve-2024-21762-explained
- https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion
- https://www.infrahunter.com/research/two-open-directories-on-a-singapore-vps
- https://radar.cloudflare.com/routing/as45758
- https://investor.jasmine.com/storage/downloads/shareholders-meetings/egm01-2025/20241209-jas-egm01-2025-enc03-en.pdf
- https://x.com/Huntio/status/2083236288660918528
- https://hunt.io/blog/introducing-hunt-v3
- https://x.com/Huntio/status/2085033123285217500
- https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/
- https://investor.jasmine.com/en/shareholder-information/major-shareholders
- https://cyberpress.org/hackers-exploit-fortigate-ssl-vpn-flaw-to-breach-thai-isp-and-deploy-meshcentral-backdoor/