Fast Facts
- Attackers exploited Fortinet CVE-2024-21762 to gain initial access, leveraging a fully developed toolkit targeting VPN vulnerabilities.
- They maintained persistent, covert control within 3BB’s network using MeshCentral as a hidden backdoor for remote management and lateral movement.
- The primary goal was to extract subscriber data, particularly targeting RADIUS databases, and potentially compromise associated networks like Jasmine.
Threat, Techniques, and Targets
An attacker gained access to 3BB, a large broadband company in Thailand. They used a tool called MeshCentral to control internal computers remotely. The attacker maintained the backdoor by setting up a hidden MeshCentral agent that connected to a command server at www.ayuthayatech[.]com under the group name TH-3BB.
The attacker operated inside the network for some time. They exploited a server left open online, which held their tools and the list of machines they controlled. They accessed more than 55 internal systems using SSH and searched for stored passwords, database logins, and SSH keys. They also planted web shells and added SSH keys as backups.
Their main goal was to steal subscriber data. They targeted the RADIUS databases, which store customer login credentials. They also appeared to target another company’s network, Jasmine, that shares infrastructure with 3BB. The initial point of entry is not confirmed, but evidence shows they targeted a FortiGate SSL-VPN gateway using a serious flaw, CVE-2024-21762, in 2024.
Impact, Implications, and Remediation
The attacker’s actions could lead to serious security issues. They gained full control of internal systems and may have accessed sensitive subscriber information. Their ability to plant web shells and add SSH keys allows them to re-enter the network even after initial detection.
It is important to follow recommended security steps. Organizations should patch or verify their FortiGate SSL-VPN appliances against CVE-2024-21762. They should also check for unexpected MeshCentral agents and unknown connections. Rotating passwords and SSH keys is crucial because the attacker may have copied or accessed them. Furthermore, organizations need to search for hidden backdoors, web shells, and new remote-management software. Logs and evidence should be preserved before removing any backdoors, as the attacker used scripts to erase traces.
Since the attacker’s toolset and indicators are well documented, organizations should review the full report and consult with their vendors or security authorities for specific remediation guidance.
Stay Ahead with the Latest Tech Trends
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
