Thai Broadband Provider Hacked via Fortinet Vulnerability
A threat actor targeted multiple vulnerabilities in Fortinet and F5 products to gain access to Thai broadband provider 3BB’s systems, Hunt.io reports.
The attack was discovered after the hackers left their intrusion arsenal in an open directory hosted on infrastructure in Thailand.
The directory contained 298 files across 30 subdirectories: multiple exploitation scripts, brute-force and privilege escalation tools, credential harvesting scripts, an inventory of compromised machines, and a MeshCentral instance agent configured as a persistent backdoor.
“The files were tagged across operational categories such as Exploit, Victim, Config, and History, consistent with an active staging environment,” Hunt.ionotes.
The tools, the cybersecurity firm says, were crafted specifically for 3BB (Triple T Broadband), one of the largest providers of fixed-line broadband services in Thailand, with millions of users, and Jasmine, the company that previously owned Triple T Broadband.
Initial access was obtained through careful fingerprinting of a FortiGate SSL-VPN endpoint...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE