Exposed Attacker Server Reveals FortiGate SSL-VPN Breach and MeshCentral Root Backdoor at Thai ISP 3BB
An open directory on attacker server 92.63.180[.]133 holding 298 files exposed an ongoing intrusion at Thai broadband provider Triple T Broadband (3BB), built around a FortiGate SSL-VPN exploit (CVE-2024-21762), root-level MeshCentral persistence, and a…
Hunt.io's discovery on June 3, 2026 of an exposed staging directory on 92.63.180[.]133 (port 8888 per one source) — containing 298 files of exploits, credential-harvesting scripts, session cookies, and a device inventory — detailed an intrusion into Triple T Broadband's 3BB brand, one of Thailand's largest broadband providers. All three reports agree the attacker held root on internal servers (internal execution confirmed at 10.11.152.63 per one source) and maintained hidden MeshCentral agents reporting to www.ayuthayatech[.]com under device group TH-3BB, plus a hidden SUID backdoor at /usr/local/bin/.rc per one source. The toolkit included a full working exploit for FortiOS SSL-VPN flaw CVE-2024-21762 (out-of-bounds write, CVSS 9.8, KEV-listed since February 2024) targeting a FortiGate 60F at mail.3bb.co[.]th:10443. On the entry vector, sources disagree: two reports state the actor exploited CVE-2024-21762 via heap spraying and a ROP chain launching a Node.js reverse shell, while The Hacker News holds that the initial access vector remains unproven despite the exploit being present. Post-exploitation included Dirty COW/PwnKit privilege escalation, credential harvesting (SSH keys, database passwords, SNMP strings), SSH password spraying against more than 55 internal machines, planted web shells, added SSH keys, and targeting of RADIUS subscriber credential databases — though exfiltration was not confirmed. Attackers also exploited Ghostcat (CVE-2020-1938) on an internal Pentaho/Tomcat server, per one source. A stolen OpenVPN certificate and private key from Triple T's PKI may still be valid and require revocation. A cleanup script wiped logs, shell histories, and web shells while deliberately preserving the MeshCentral agent and the SUID backdoor.
- Exposed attacker staging server at 92.63.180[.]133 (open directory on port 8888 per one source) held 298 files documenting the intrusion, discovered by Hunt.io on June 3, 2026.
- Victim: Triple T Broadband's 3BB brand, one of Thailand's largest broadband providers; internal execution confirmed at 10.11.152.63.
- Toolkit contained a full exploit for CVE-2024-21762 (FortiOS SSL-VPN out-of-bounds write, CVSS 9.8, KEV-listed since February 2024) against a FortiGate 60F at mail.3bb.co[.]th:10443; two reports say it was used with heap spraying and a ROP…
- MeshCentral agents (device group TH-3BB, C2 www.ayuthayatech[.]com) ran as root for persistence; a hidden SUID backdoor at /usr/local/bin/.rc was also planted per one source; both were deliberately preserved by the cleanup script.
- Post-exploitation included Dirty COW/PwnKit privilege escalation, harvesting of SSH keys, database passwords, SNMP strings, and RADIUS subscriber credential databases; exfiltration was not confirmed.
- SSH password spraying hit more than 55 internal machines; web shells and attacker SSH keys were added for persistence.
- Attackers exploited Ghostcat (CVE-2020-1938) against an internal Pentaho/Tomcat server, per one report.
- A stolen OpenVPN certificate and private key from Triple T's PKI may still be valid and require revocation.
Coverage timelineoldest first · each row is one article
- · 1d agoHackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News· 75
Exposed attacker staging server reveals intrusion of Thai broadband provider 3BB via actively exploited FortiGate SSL-VPN flaw CVE-2024-21762.
- · 1d ago3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News· 70
Hunt.io found an attacker holding root access inside Thai ISP 3BB via a MeshCentral backdoor, targeting subscriber RADIUS credential databases.
- · 16h agoHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers· 78
Threat actors exploited FortiOS SSL-VPN flaw CVE-2024-21762 to breach Thai ISP Triple T Broadband, gaining root-level persistence via MeshCentral agents.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1938 | Ghostcat (CVE-2020-1938): Unauthenticated File Read/JSP RCE via AJP in Apache Tomcat CVE-2020-1938 ('Ghostcat') is an improper privilege management flaw in Apache Tomcat's Apache JServ Protocol (AJP) connector, which shipped enabled by default listening on all interfaces (typically port 8009) in Tomcat 9.0.0.M1-9.0.0.30, 8.5.0-8.5.50 and 7.0.0-7.0.99, and which treats AJP connections as far more trusted than equivalent HTTP connections. An attacker who can reach the AJP port without authentication can inject crafted AJP attributes to make Tomcat return arbitrary files from anywhere in the web application or process any file in the web application as JSP. If the application allows file uploads stored within the web application (or the attacker can otherwise control file content), this escalates to unauthenticated remote code execution. Exposure is conditional: only deployments where the AJP port is reachable by untrusted users are at risk, but Tomcat's very large installed base, including vendor bundles from Oracle, NetApp, Debian, openSUSE, Fedora and BlackBerry, means many hundreds of thousands of systems are potentially affected. The flaw is known to be exploited: it was added to CISA's KEV on 2022-03-03, EPSS estimates a 99.3% probability of exploitation within 30 days (100th percentile), and mass scanning of exposed Tomcat AJP ports was publicly reported. Do: Upgrade to Apache Tomcat 9.0.31, 8.5.51, or 7.0.100 or later, noting that the hardened default AJP connector configuration in these releases may require small configuration changes after upgrade. If you cannot upgrade, disable the AJP connector if unused, or bind it to localhost/restrict firewall access so port 8009 is not reachable by untrusted users. Check whether the AJP port is exposed to the internet and whether any web application allows file uploads into the web application directory, since that is what converts file read into remote code execution. | 9.8 | 99% | KEV PoC |
| masshundreds of thousands of internet-exposed Tomcat AJP endpoints (order of magnitude: 100,000+ exposed systems) | |
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) |