Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
Threat actors exploited FortiOS SSL-VPN flaw CVE-2024-21762 to breach Thai ISP Triple T Broadband, gaining root-level persistence via MeshCentral agents.
Attackers exploited CVE-2024-21762, an out-of-bounds write enabling unauthenticated RCE in FortiOS SSL-VPN, against Triple T Broadband's FortiGate 60F at mail.3bb.co.th, launching a Node.js reverse shell via a ROP payload. Hunt.io uncovered the operation through an exposed staging directory at 92.63.180[.]133:8888 containing 298 files of exploits, credential-harvesting scripts, session cookies, and a device inventory. Post-compromise, the actors deployed MeshCentral agents (device group TH-3BB, C2 www.ayuthayatech.com) running as root, plus a hidden SUID backdoor at /usr/local/bin/.rc, and also targeted an internal Pentaho/Tomcat server with Ghostcat (CVE-2020-1938). A cleanup script removed logs, shell histories, and web shells while deliberately preserving the MeshCentral agent and SUID backdoor.
- CVE-2024-21762 out-of-bounds write in FortiOS SSL-VPN gave unauthenticated RCE on FortiGate 60F.
- MeshCentral backdoor (group TH-3BB, C2 www.ayuthayatech.com) ran as root on multiple systems.
- Exposed staging directory at 92.63.180[.]133:8888 held 298 files of exploits, credentials, and device inventory.
- Attackers harvested RADIUS database credentials and exploited Ghostcat (CVE-2020-1938) on internal Tomcat.
- Cleanup script cleared logs and web shells but preserved MeshCentral agent and SUID backdoor.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1938 | Ghostcat (CVE-2020-1938): Unauthenticated File Read/JSP RCE via AJP in Apache Tomcat CVE-2020-1938 ('Ghostcat') is an improper privilege management flaw in Apache Tomcat's Apache JServ Protocol (AJP) connector, which shipped enabled by default listening on all interfaces (typically port 8009) in Tomcat 9.0.0.M1-9.0.0.30, 8.5.0-8.5.50 and 7.0.0-7.0.99, and which treats AJP connections as far more trusted than equivalent HTTP connections. An attacker who can reach the AJP port without authentication can inject crafted AJP attributes to make Tomcat return arbitrary files from anywhere in the web application or process any file in the web application as JSP. If the application allows file uploads stored within the web application (or the attacker can otherwise control file content), this escalates to unauthenticated remote code execution. Exposure is conditional: only deployments where the AJP port is reachable by untrusted users are at risk, but Tomcat's very large installed base, including vendor bundles from Oracle, NetApp, Debian, openSUSE, Fedora and BlackBerry, means many hundreds of thousands of systems are potentially affected. The flaw is known to be exploited: it was added to CISA's KEV on 2022-03-03, EPSS estimates a 99.3% probability of exploitation within 30 days (100th percentile), and mass scanning of exposed Tomcat AJP ports was publicly reported. Do: Upgrade to Apache Tomcat 9.0.31, 8.5.51, or 7.0.100 or later, noting that the hardened default AJP connector configuration in these releases may require small configuration changes after upgrade. If you cannot upgrade, disable the AJP connector if unused, or bind it to localhost/restrict firewall access so port 8009 is not reachable by untrusted users. Check whether the AJP port is exposed to the internet and whether any web application allows file uploads into the web application directory, since that is what converts file read into remote code execution. | 9.8 | 99% | KEV PoC |
| masshundreds of thousands of internet-exposed Tomcat AJP endpoints (order of magnitude: 100,000+ exposed systems) | |
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | ayuthayatech.com | fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A |
| domain | co.th | focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe |
| domain | hunt.io | 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp |
| domain | triplet.co | ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t |
Full article818 words · extracted from gbhackers.com · click to collapse
Threat actors exploited the critical FortiGate SSL-VPN vulnerability CVE-2024-21762 to target the Thai broadband provider Triple T Broadband (3BB). They gained access to its internal environment and deployed MeshCentral remote management agents for persistent control.
Hunt.io uncovered the operation after AttackCapture identified an internet-accessible directory hosted on a server in Thailand. This directory contained exploitation tools, credential-harvesting scripts, VPN material, session cookies, and an inventory of compromised devices.
When first captured on June 3, 2026, the directory, located at 92.63.180[.]133:8888, reportedly held 298 files across 30 subdirectories.
FortiGate Exploitation Chain
The recovered tools indicated that the attackers initially focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443.
Scripts named forti1.sh through forti8.sh performed device fingerprinting, checked the SSL-VPN interface for several known FortiGate vulnerabilities, and tested organization-specific credentials against the VPN login endpoint.
The attackers ultimately selected CVE-2024-21762, an out-of-bounds write vulnerability in FortiOS SSL-VPN that allows unauthenticated remote code execution on affected devices.
Their toolkit included proof-of-concept, validation, and exploitation scripts designed to identify a vulnerable service, trigger controlled crashes, and optimize payloads for the FortiGate 60F platform.
![AttackCapture™ view of the exposed directory at 92.63.180[.]133:8888, showing 298 files across 30 subdirectories totaling 19 MB. (Source: Hunt)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXGTpT71N_0tCerkpFQ8vhXA_CyWQOTdO6EYuDyk0kIrhax3Lk3-KZi3UZKua7JR_Hj3pH9HSSiTW-fMqUDjqq3XOrUS5pwdS4M4wqiK0uf_-Ji3dpvv4vFd21AobYgYjjqyLQZLpVfjGFs4ZGKrMtaowFOMd5KaYAzo0J7ggBTNHgGHPXFam1k7wdQXf5/s1600/Thailand+Campaign+-+figure+1%20%281%29.webp)
The full exploit chain reportedly sent crafted requests against /remote/hostcheck_validate to prepare memory and execute a return-oriented programming (ROP) payload.
This payload launched a Node.js-based reverse shell that connected back to the staging server at 92.63.180[.]133 over port 9443.
Additionally, the attackers attempted to download the corresponding FortiOS firmware image, likely to identify device-specific ROP gadgets and enhance exploitation reliability.
One script included the target appliance’s serial number, FGT60FTK2209FY0V, to impersonate the device while requesting firmware.
After gaining access, the threat actors deployed MeshCentral, a legitimate open-source remote monitoring and management platform, as a backdoor.
The recovered meshagent.msh configuration identified a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx.
A devices.json file contained an inventory of enrolled systems, including hostnames, internal and public IP addresses, operating system details, connection statuses, and agent privilege levels.
Several entries were reportedly active, with agents running as root, indicating that the attackers had established administrative control over multiple systems.

The attackers used deployment scripts such as mesh_fix.sh, mi2_vps.sh, and ghost_mesh.sh to automate installation, test outbound connectivity, and check for endpoint security products before deploying the MeshCentral agent.
The exposed toolkit included scripts targeting 3BB’s internal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested that some commands were executed from an already compromised internal host.
Post-compromise tooling included SSH password-spraying utilities, MySQL enumeration scripts, web shell deployment routines, and credential harvesting scripts. The cred_hunt.sh script searched for SSH private keys, PHP configuration files, database credentials, SNMP community strings, and shell history.
Concerningly, the db_creds.sh script targeted RADIUS databases named radius_corp, radiusinfo, and job_radius. These systems may contain subscriber authentication data and network device information, making them high-value targets for attackers seeking to expand access or collect credentials.
The attackers also targeted an internal Pentaho/Tomcat server at 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a compromised Linux application server.
A cleanup script, cleanup_target.sh, was designed to remove exploit files, clear Linux logs, erase shell histories, and delete web shells. However, it deliberately preserved the MeshCentral agent and a hidden SUID backdoor at /usr/local/bin/.rc, allowing the attackers to retain access while destroying evidence.
Organizations should immediately patch FortiGate appliances, inspect VPN logs for suspicious authentication or SSL-VPN activity, search for unauthorized MeshCentral agents, and rotate VPN, SSH, database, RADIUS, and application credentials where a compromise is suspected.
Ioc
| Type | Indicator | Description |
|---|---|---|
| Attacker infrastructure | 92.63.180[.]133 | Staging server hosting exploit tooling |
| Open directory | 92.63.180[.]133:8888 | Publicly accessible attacker directory |
| Reverse shell | 92.63.180[.]133:9443 | Callback listener used by FortiGate exploit |
| MeshCentral C2 | www.ayuthayatech[.]com | Remote-management server used for persistence |
| MeshCentral path | /agent.ashx | WebSocket agent communication endpoint |
| Mesh group | TH-3BB | Actor-defined MeshCentral device group |
| FortiGate target | mail.3bb.co[.]th:10443 | Targeted FortiGate SSL-VPN endpoint |
| Web portal target | agent.3bb.co[.]th | Targeted internal 3BB agent portal |
| F5 BIG-IP target | 110.164.192[.]228 | Management interface probed for vulnerabilities |
| VPN endpoint | 110.164.129[.]67:443 | Jasmine OpenVPN endpoint in recovered configuration |
| Internal target | 10.11.152[.]4:8009 | Pentaho/Tomcat host targeted via Ghostcat |
| Persistence | /usr/local/bin/.rc | Hidden SUID backdoor path |
| MeshCentral artifact | meshagent.msh | Agent configuration file |
| Device inventory | devices.json | List of MeshCentral-enrolled systems |
| Web shell | /var/www/html/info.php | PHP web shell created through MySQL abuse |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/hackers-exploit-fortigate-ssl-vpn-flaw/