⚠️ Open directory exposes live ISP intrusion, RADIUS subscriber creds the objective
An open directory exposed on a server in Thailand revealed an active intrusion operation targeting two major broadband providers, primarily 3BB (Triple T Broadband). The attacker exploited CVE-2024-21762 to gain remote code execution on a FortiGate 60F SSL-VPN device. The exposed files included exploitation scripts, privilege escalation tools, brute-force utilities, and a MeshCentral agent configured as a persistent backdoor. The attacker aimed to extract subscriber authentication data from RADIUS databases and had valid OpenVPN certificates and active session cookies, indicating deep network access. The attacker also prepared cleanup scripts to remove traces while maintaining persistence. Hunt.io notified affected parties and CERT prior to public disclosure.
AI Analysis
Technical Summary
Hunt.io discovered an open directory hosted on infrastructure in Thailand containing 298 files related to an ongoing intrusion against 3BB and a linked broadband provider. The attacker leveraged CVE-2024-21762 to remotely execute code on a FortiGate 60F SSL-VPN device. The directory contained a full operational toolkit including reconnaissance scripts, exploitation payloads, brute-force tools targeting internal IP ranges, credential harvesting scripts focused on RADIUS subscriber authentication databases, and a MeshCentral remote management agent configured for persistence. The attacker possessed valid OpenVPN certificates issued by the target's PKI and active session cookies, demonstrating successful network compromise. The staging server also functioned as a reverse shell callback host. The attacker pre-staged anti-forensic cleanup scripts but preserved the MeshCentral backdoor. Hunt.io responsibly disclosed the findings to affected organizations and CERT with TLP:AMBER.
Potential Impact
The attacker achieved remote code execution on a FortiGate SSL-VPN device, enabling deep network access into the broadband providers' internal infrastructure. This allowed extraction of subscriber authentication credentials from RADIUS databases, potentially compromising subscriber accounts. The attacker established persistent remote access via MeshCentral agents and possessed valid VPN certificates and session cookies, indicating extensive control over the network environment. The operation included lateral movement and credential harvesting, increasing the risk of further compromise and data exfiltration. The presence of cleanup scripts suggests attempts to evade detection and forensic analysis.
Mitigation Recommendations
Patch status for CVE-2024-21762 should be verified with Fortinet's official advisories; remediation likely involves applying vendor-provided patches or updates to FortiGate SSL-VPN devices. Organizations should audit their FortiGate SSL-VPN deployments for signs of compromise, including unauthorized MeshCentral agents and unexpected VPN certificates or session tokens. Since the attacker used a known CVE, applying the official fix is critical. Hunt.io's disclosure indicates affected parties were notified, but organizations should conduct thorough incident response and credential resets for impacted RADIUS databases. Monitoring for persistence mechanisms such as MeshCentral agents is recommended. No indication that the vulnerability is in a cloud service; remediation responsibility lies with the affected organizations.
⚠️ Open directory exposes live ISP intrusion, RADIUS subscriber creds the objective
Description
An open directory exposed on a server in Thailand revealed an active intrusion operation targeting two major broadband providers, primarily 3BB (Triple T Broadband). The attacker exploited CVE-2024-21762 to gain remote code execution on a FortiGate 60F SSL-VPN device. The exposed files included exploitation scripts, privilege escalation tools, brute-force utilities, and a MeshCentral agent configured as a persistent backdoor. The attacker aimed to extract subscriber authentication data from RADIUS databases and had valid OpenVPN certificates and active session cookies, indicating deep network access. The attacker also prepared cleanup scripts to remove traces while maintaining persistence. Hunt.io notified affected parties and CERT prior to public disclosure.
Reddit Discussion
AttackCapture surfaced an open directory that mapped an active operation against one of Thailand's largest broadband providers and, in parallel, a second linked provider. Scope and objective are clearer than usual because the operator left the whole staging server exposed.
The tooling references internal 10.11.x.x subnets and was run from a compromised host inside the network. The objective was subscriber authentication data from the RADIUS infrastructure.
A valid OpenVPN cert from the provider's own PKI and active session cookies for the linked provider show the operation reached both companies. A second MeshCentral group referencing another organization was shared with the relevant CERT, not published.
https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hunt.io discovered an open directory hosted on infrastructure in Thailand containing 298 files related to an ongoing intrusion against 3BB and a linked broadband provider. The attacker leveraged CVE-2024-21762 to remotely execute code on a FortiGate 60F SSL-VPN device. The directory contained a full operational toolkit including reconnaissance scripts, exploitation payloads, brute-force tools targeting internal IP ranges, credential harvesting scripts focused on RADIUS subscriber authentication databases, and a MeshCentral remote management agent configured for persistence. The attacker possessed valid OpenVPN certificates issued by the target's PKI and active session cookies, demonstrating successful network compromise. The staging server also functioned as a reverse shell callback host. The attacker pre-staged anti-forensic cleanup scripts but preserved the MeshCentral backdoor. Hunt.io responsibly disclosed the findings to affected organizations and CERT with TLP:AMBER.
Potential Impact
The attacker achieved remote code execution on a FortiGate SSL-VPN device, enabling deep network access into the broadband providers' internal infrastructure. This allowed extraction of subscriber authentication credentials from RADIUS databases, potentially compromising subscriber accounts. The attacker established persistent remote access via MeshCentral agents and possessed valid VPN certificates and session cookies, indicating extensive control over the network environment. The operation included lateral movement and credential harvesting, increasing the risk of further compromise and data exfiltration. The presence of cleanup scripts suggests attempts to evade detection and forensic analysis.
Defensive Guidance
Patch status for CVE-2024-21762 should be verified with Fortinet's official advisories; remediation likely involves applying vendor-provided patches or updates to FortiGate SSL-VPN devices. Organizations should audit their FortiGate SSL-VPN deployments for signs of compromise, including unauthorized MeshCentral agents and unexpected VPN certificates or session tokens. Since the attacker used a known CVE, applying the official fix is critical. Hunt.io's disclosure indicates affected parties were notified, but organizations should conduct thorough incident response and credential resets for impacted RADIUS databases. Monitoring for persistence mechanisms such as MeshCentral agents is recommended. No indication that the vulnerability is in a cloud service; remediation responsibility lies with the affected organizations.
Technical Details
- Source Type
- Subreddit
- ThreatIntelligence+threatintel+websecurityresearch
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aa8d14c55bf5e2cf5290cfa
Added to database: 09/15/2026, 05:02:04 UTC
Last enriched: 09/15/2026, 05:02:16 UTC
Last updated: 09/15/2026, 07:01:25 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.