ZeroHour
GBHackerspublished ()ingested Divya
Part of a story covered by 3 sources: “Exposed Attacker Server Reveals FortiGate SSL-VPN Breach and MeshCentral Root Backdoor at Thai ISP 3BB” — merged summary and timeline →

Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor

highExploit / PoC exploited in the wildimportance 78CVE-2024-21762CVE-2020-1938
AI summary · glm-5.3

Threat actors exploited FortiOS SSL-VPN flaw CVE-2024-21762 to breach Thai ISP Triple T Broadband, gaining root-level persistence via MeshCentral agents.

Attackers exploited CVE-2024-21762, an out-of-bounds write enabling unauthenticated RCE in FortiOS SSL-VPN, against Triple T Broadband's FortiGate 60F at mail.3bb.co.th, launching a Node.js reverse shell via a ROP payload. Hunt.io uncovered the operation through an exposed staging directory at 92.63.180[.]133:8888 containing 298 files of exploits, credential-harvesting scripts, session cookies, and a device inventory. Post-compromise, the actors deployed MeshCentral agents (device group TH-3BB, C2 www.ayuthayatech.com) running as root, plus a hidden SUID backdoor at /usr/local/bin/.rc, and also targeted an internal Pentaho/Tomcat server with Ghostcat (CVE-2020-1938). A cleanup script removed logs, shell histories, and web shells while deliberately preserving the MeshCentral agent and SUID backdoor.

  • CVE-2024-21762 out-of-bounds write in FortiOS SSL-VPN gave unauthenticated RCE on FortiGate 60F.
  • MeshCentral backdoor (group TH-3BB, C2 www.ayuthayatech.com) ran as root on multiple systems.
  • Exposed staging directory at 92.63.180[.]133:8888 held 298 files of exploits, credentials, and device inventory.
  • Attackers harvested RADIUS database credentials and exploited Ghostcat (CVE-2020-1938) on internal Tomcat.
  • Cleanup script cleared logs and web shells but preserved MeshCentral agent and SUID backdoor.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1938
Ghostcat (CVE-2020-1938): Unauthenticated File Read/JSP RCE via AJP in Apache Tomcat

CVE-2020-1938 ('Ghostcat') is an improper privilege management flaw in Apache Tomcat's Apache JServ Protocol (AJP) connector, which shipped enabled by default listening on all interfaces (typically port 8009) in Tomcat 9.0.0.M1-9.0.0.30, 8.5.0-8.5.50 and 7.0.0-7.0.99, and which treats AJP connections as far more trusted than equivalent HTTP connections. An attacker who can reach the AJP port without authentication can inject crafted AJP attributes to make Tomcat return arbitrary files from anywhere in the web application or process any file in the web application as JSP. If the application allows file uploads stored within the web application (or the attacker can otherwise control file content), this escalates to unauthenticated remote code execution. Exposure is conditional: only deployments where the AJP port is reachable by untrusted users are at risk, but Tomcat's very large installed base, including vendor bundles from Oracle, NetApp, Debian, openSUSE, Fedora and BlackBerry, means many hundreds of thousands of systems are potentially affected. The flaw is known to be exploited: it was added to CISA's KEV on 2022-03-03, EPSS estimates a 99.3% probability of exploitation within 30 days (100th percentile), and mass scanning of exposed Tomcat AJP ports was publicly reported.

Do: Upgrade to Apache Tomcat 9.0.31, 8.5.51, or 7.0.100 or later, noting that the hardened default AJP connector configuration in these releases may require small configuration changes after upgrade. If you cannot upgrade, disable the AJP connector if unused, or bind it to localhost/restrict firewall access so port 8009 is not reachable by untrusted users. Check whether the AJP port is exposed to the internet and whether any web application allows file uploads into the web application directory, since that is what converts file read into remote code execution.

9.899% KEV PoC
  • Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50, 7.0.0 to 7.0.99 (AJP connector in default configuration)
  • Apache Geode
  • Fedora Project Fedora (Tomcat packaging)
  • +9 more
masshundreds of thousands of internet-exposed Tomcat AJP endpoints (order of magnitude: 100,000+ exposed systems)
CVE-2024-21762
Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy

CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted.

Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority.

9.884% KEV ransomware
  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7
mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans)

Indicators of compromiseAll →

TypeIndicatorContext
domainayuthayatech.comfied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A
domainco.thfocused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe
domainhunt.io10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp
domaintriplet.coernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t
Full article818 words · extracted from gbhackers.com · click to collapse

Threat actors exploited the critical FortiGate SSL-VPN vulnerability CVE-2024-21762 to target the Thai broadband provider Triple T Broadband (3BB). They gained access to its internal environment and deployed MeshCentral remote management agents for persistent control.

Hunt.io uncovered the operation after AttackCapture identified an internet-accessible directory hosted on a server in Thailand. This directory contained exploitation tools, credential-harvesting scripts, VPN material, session cookies, and an inventory of compromised devices.

When first captured on June 3, 2026, the directory, located at 92.63.180[.]133:8888, reportedly held 298 files across 30 subdirectories.

FortiGate Exploitation Chain

The recovered tools indicated that the attackers initially focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443.

Scripts named forti1.sh through forti8.sh performed device fingerprinting, checked the SSL-VPN interface for several known FortiGate vulnerabilities, and tested organization-specific credentials against the VPN login endpoint.

The attackers ultimately selected CVE-2024-21762, an out-of-bounds write vulnerability in FortiOS SSL-VPN that allows unauthenticated remote code execution on affected devices.

Their toolkit included proof-of-concept, validation, and exploitation scripts designed to identify a vulnerable service, trigger controlled crashes, and optimize payloads for the FortiGate 60F platform.

AttackCapture™ view of the exposed directory at 92.63.180[.]133:8888, showing 298 files across 30 subdirectories totaling 19 MB. (Source: Hunt)
AttackCapture™ view of the exposed directory at 92.63.180[.]133:8888, showing 298 files across 30 subdirectories totaling 19 MB. (Source: Hunt)

The full exploit chain reportedly sent crafted requests against /remote/hostcheck_validate to prepare memory and execute a return-oriented programming (ROP) payload.

This payload launched a Node.js-based reverse shell that connected back to the staging server at 92.63.180[.]133 over port 9443.

Additionally, the attackers attempted to download the corresponding FortiOS firmware image, likely to identify device-specific ROP gadgets and enhance exploitation reliability.

One script included the target appliance’s serial number, FGT60FTK2209FY0V, to impersonate the device while requesting firmware.

After gaining access, the threat actors deployed MeshCentral, a legitimate open-source remote monitoring and management platform, as a backdoor.

The recovered meshagent.msh configuration identified a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx.

A devices.json file contained an inventory of enrolled systems, including hostnames, internal and public IP addresses, operating system details, connection statuses, and agent privilege levels.

Several entries were reportedly active, with agents running as root, indicating that the attackers had established administrative control over multiple systems.

Hunt.io AttackCapture of the exposed open directory containing the forti1.sh to forti8.sh reconnaissance scripts targeting the FortiGate SSL-VPN service (Source: Hunt)
Hunt.io AttackCapture of the exposed open directory containing the forti1.sh to forti8.sh reconnaissance scripts targeting the FortiGate SSL-VPN service (Source: Hunt)

The attackers used deployment scripts such as mesh_fix.sh, mi2_vps.sh, and ghost_mesh.sh to automate installation, test outbound connectivity, and check for endpoint security products before deploying the MeshCentral agent.

The exposed toolkit included scripts targeting 3BB’s internal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested that some commands were executed from an already compromised internal host.

Post-compromise tooling included SSH password-spraying utilities, MySQL enumeration scripts, web shell deployment routines, and credential harvesting scripts. The cred_hunt.sh script searched for SSH private keys, PHP configuration files, database credentials, SNMP community strings, and shell history.

Concerningly, the db_creds.sh script targeted RADIUS databases named radius_corp, radiusinfo, and job_radius. These systems may contain subscriber authentication data and network device information, making them high-value targets for attackers seeking to expand access or collect credentials.

The attackers also targeted an internal Pentaho/Tomcat server at 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a compromised Linux application server.

A cleanup script, cleanup_target.sh, was designed to remove exploit files, clear Linux logs, erase shell histories, and delete web shells. However, it deliberately preserved the MeshCentral agent and a hidden SUID backdoor at /usr/local/bin/.rc, allowing the attackers to retain access while destroying evidence.

Organizations should immediately patch FortiGate appliances, inspect VPN logs for suspicious authentication or SSL-VPN activity, search for unauthorized MeshCentral agents, and rotate VPN, SSH, database, RADIUS, and application credentials where a compromise is suspected.

Ioc

TypeIndicatorDescription
Attacker infrastructure92.63.180[.]133Staging server hosting exploit tooling
Open directory92.63.180[.]133:8888Publicly accessible attacker directory
Reverse shell92.63.180[.]133:9443Callback listener used by FortiGate exploit
MeshCentral C2www.ayuthayatech[.]comRemote-management server used for persistence
MeshCentral path/agent.ashxWebSocket agent communication endpoint
Mesh groupTH-3BBActor-defined MeshCentral device group
FortiGate targetmail.3bb.co[.]th:10443Targeted FortiGate SSL-VPN endpoint
Web portal targetagent.3bb.co[.]thTargeted internal 3BB agent portal
F5 BIG-IP target110.164.192[.]228Management interface probed for vulnerabilities
VPN endpoint110.164.129[.]67:443Jasmine OpenVPN endpoint in recovered configuration
Internal target10.11.152[.]4:8009Pentaho/Tomcat host targeted via Ghostcat
Persistence/usr/local/bin/.rcHidden SUID backdoor path
MeshCentral artifactmeshagent.mshAgent configuration file
Device inventorydevices.jsonList of MeshCentral-enrolled systems
Web shell/var/www/html/info.phpPHP web shell created through MySQL abuse

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/