Skip to main content

⚠️ Open directory exposes live ISP intrusion, RADIUS subscriber creds the objective

0
Medium
Published: 09/14/2026 (09/14/2026, 16:29:08 UTC)
Source: Reddit ThreatIntel

Description

An open directory exposed on a server in Thailand revealed an active intrusion operation targeting two major broadband providers, primarily 3BB (Triple T Broadband). The attacker exploited CVE-2024-21762 to gain remote code execution on a FortiGate 60F SSL-VPN device. The exposed files included exploitation scripts, privilege escalation tools, brute-force utilities, and a MeshCentral agent configured as a persistent backdoor. The attacker aimed to extract subscriber authentication data from RADIUS databases and had valid OpenVPN certificates and active session cookies, indicating deep network access. The attacker also prepared cleanup scripts to remove traces while maintaining persistence. Hunt.io notified affected parties and CERT prior to public disclosure.

Reddit Discussion

r/threatintel·posted by u/Straight-Practice-99
00

AttackCapture surfaced an open directory that mapped an active operation against one of Thailand's largest broadband providers and, in parallel, a second linked provider. Scope and objective are clearer than usual because the operator left the whole staging server exposed.

The tooling references internal 10.11.x.x subnets and was run from a compromised host inside the network. The objective was subscriber authentication data from the RADIUS infrastructure.

A valid OpenVPN cert from the provider's own PKI and active session cookies for the linked provider show the operation reached both companies. A second MeshCentral group referencing another organization was shared with the relevant CERT, not published.

https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 05:02:16 UTC

Technical Analysis

Hunt.io discovered an open directory hosted on infrastructure in Thailand containing 298 files related to an ongoing intrusion against 3BB and a linked broadband provider. The attacker leveraged CVE-2024-21762 to remotely execute code on a FortiGate 60F SSL-VPN device. The directory contained a full operational toolkit including reconnaissance scripts, exploitation payloads, brute-force tools targeting internal IP ranges, credential harvesting scripts focused on RADIUS subscriber authentication databases, and a MeshCentral remote management agent configured for persistence. The attacker possessed valid OpenVPN certificates issued by the target's PKI and active session cookies, demonstrating successful network compromise. The staging server also functioned as a reverse shell callback host. The attacker pre-staged anti-forensic cleanup scripts but preserved the MeshCentral backdoor. Hunt.io responsibly disclosed the findings to affected organizations and CERT with TLP:AMBER.

Potential Impact

The attacker achieved remote code execution on a FortiGate SSL-VPN device, enabling deep network access into the broadband providers' internal infrastructure. This allowed extraction of subscriber authentication credentials from RADIUS databases, potentially compromising subscriber accounts. The attacker established persistent remote access via MeshCentral agents and possessed valid VPN certificates and session cookies, indicating extensive control over the network environment. The operation included lateral movement and credential harvesting, increasing the risk of further compromise and data exfiltration. The presence of cleanup scripts suggests attempts to evade detection and forensic analysis.

Defensive Guidance

Patch status for CVE-2024-21762 should be verified with Fortinet's official advisories; remediation likely involves applying vendor-provided patches or updates to FortiGate SSL-VPN devices. Organizations should audit their FortiGate SSL-VPN deployments for signs of compromise, including unauthorized MeshCentral agents and unexpected VPN certificates or session tokens. Since the attacker used a known CVE, applying the official fix is critical. Hunt.io's disclosure indicates affected parties were notified, but organizations should conduct thorough incident response and credential resets for impacted RADIUS databases. Monitoring for persistence mechanisms such as MeshCentral agents is recommended. No indication that the vulnerability is in a cloud service; remediation responsibility lies with the affected organizations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ThreatIntelligence+threatintel+websecurityresearch
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa8d14c55bf5e2cf5290cfa

Added to database: 09/15/2026, 05:02:04 UTC

Last enriched: 09/15/2026, 05:02:16 UTC

Last updated: 09/15/2026, 07:01:25 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses