Executive Summary
In June 2026, threat actors compromised 3BB, Thailand's largest broadband provider, using a sophisticated attack that leveraged CVE-2024-21762, a critical Fortinet FortiGate SSL-VPN vulnerability. The attackers maintained persistent access through MeshCentral remote management tools configured as hidden backdoors, achieved root-level privileges on internal servers, and targeted RADIUS databases containing subscriber credentials. Hunt.io researchers discovered the ongoing operation through an exposed attacker server containing tools, compromised device lists, and evidence of lateral movement across 3BB's network infrastructure.
This incident exemplifies the growing trend of attackers abusing legitimate remote management tools to maintain stealth persistence while exploiting unpatched edge devices for initial access, highlighting critical gaps in network segmentation and credential management practices.
Why This Matters Now
Telecommunications providers face intensified targeting as attackers seek subscriber data and network access for espionage campaigns, while the abuse of legitimate remote management tools like MeshCentral makes detection increasingly difficult for security teams.
Attack Path Analysis
Attacker exploited CVE-2024-21762 on FortiGate SSL-VPN to gain initial access to 3BB's network, escalated privileges to root on internal servers, moved laterally across 55+ systems using SSH password spraying and credential harvesting, established persistent command and control via MeshCentral remote management tool, targeted RADIUS databases for subscriber credential exfiltration, and maintained ongoing access for potential service disruption and data theft operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploited CVE-2024-21762 vulnerability on FortiGate SSL-VPN gateway at mail.3bb.co.th to execute code without authentication and gain initial network access
Related CVEs
CVE-2024-21762
CVSS 9.8An out-of-bounds write vulnerability in FortiOS SSL-VPN allows an unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Affected Products:
Fortinet FortiOS – 6.2.0 through 6.2.15, 6.4.0 through 6.4.14, 7.0.0 through 7.0.13, 7.2.0 through 7.2.6, 7.4.0 through 7.4.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Web Shell
Remote Access Software
Password Spraying
Credentials In Files
Clear Windows Event Logs
Data from Local System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.02(g)
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Privileged Access Management
Control ID: Identity.AM-6
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21.2(a)
ISO 27001:2022 – Management of Vulnerabilities
Control ID: A.8.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Network intrusion targeting broadband provider exposes subscriber credential databases, VPN vulnerabilities, and lateral movement risks requiring enhanced segmentation and egress controls.
Internet
MeshCentral backdoor and FortiGate SSL-VPN exploitation demonstrate critical need for zero trust architecture and encrypted traffic monitoring in internet service providers.
Information Technology/IT
CVE-2024-21762 exploitation toolkit and remote management tool abuse highlight requirements for threat detection, patch management, and secure hybrid connectivity solutions.
Computer/Network Security
Advanced persistent threat using legitimate tools requires enhanced anomaly detection, east-west traffic security, and multicloud visibility for comprehensive defense strategies.
Sources
- 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentialshttps://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.htmlVerified
- Fortinet FortiOS SSL-VPN Remote Code Execution Vulnerability - FG-IR-24-015https://fortiguard.fortinet.com/psirt/FG-IR-24-015Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Thai Broadband Provider Targeted Through FortiGate SSL-VPN and MeshCentral Intrusionhttps://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusionVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the attacker's lateral movement across 55+ systems and reduced the blast radius through workload segmentation and east-west traffic enforcement. The segmented architecture would likely have limited privilege escalation scope and controlled egress paths for data exfiltration attempts.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF architecture would likely have constrained the attacker's initial network reach by limiting access scope from the compromised SSL-VPN endpoint through segmented network boundaries
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely have limited the scope of privilege escalation by constraining administrative access to specific workload boundaries rather than broad server access
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly reduced the attacker's ability to reach 55+ systems by enforcing segmented communication paths between workloads and blocking unauthorized SSH connections
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained the unauthorized MeshCentral agent's communication patterns to the external attacker infrastructure at ayuthayatech.com
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have constrained the attacker's ability to exfiltrate RADIUS subscriber data by enforcing controlled outbound data flows and blocking unauthorized database extraction attempts
With CNSF controls in place, the attacker's persistent access would likely be limited to isolated network segments, reducing the scope of potential subscriber data exposure and service disruption capabilities
Impact at a Glance
Affected Business Functions
- Internet Service Provision
- Customer Authentication Systems
- Network Infrastructure Management
- Customer Data Management
Estimated downtime: N/A
Estimated loss: N/A
RADIUS authentication databases containing subscriber login credentials for broadband internet access, potential exposure of customer authentication data and network access credentials
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement across internal systems and limit SSH access to authorized workloads only
- • Deploy egress security controls with FQDN filtering to detect and block unauthorized outbound connections to attacker command and control infrastructure like MeshCentral servers
- • Enable multicloud visibility and anomaly detection to identify suspicious remote management tool deployments and unauthorized administrative access patterns
- • Implement inline IPS with Suricata signatures to detect and block CVE-2024-21762 FortiGate exploitation attempts and other known vulnerability exploits
- • Establish encrypted traffic inspection and east-west traffic monitoring to detect credential harvesting activities and unauthorized database access attempts



