An attacker-controlled staging server at 92.63.180[.]133:8888 exposed artifacts from a suspected intrusion into Thailand's 3BB/Triple T Broadband and related Jasmine infrastructure. The operation allegedly exploited the critical FortiOS/FortiProxy SSL-VPN out-of-bounds write flaw CVE-2024-21762 against a FortiGate 60F appliance at mail.3bb.co[.]th:10443, with the server also configured to receive a FortiGate reverse shell. Recovered files included internal addresses, service-targeting data, organization-specific password lists, and an apparent Triple T Broadband OpenVPN profile containing a certificate and private key.
The operators reportedly conducted reconnaissance, credential harvesting, SSH password spraying, Linux privilege-escalation attempts, lateral-movement preparation, web-shell deployment, and anti-forensic cleanup. They deployed MeshCentral for persistent remote administration, enrolling compromised devices in a TH-3BB group configured to connect to www.ayuthayatech[.]com; the tooling also sought RADIUS databases and subscriber credentials. Evidence indicates parallel targeting of Jasmine systems, but the available artifacts do not identify the operators or establish how they obtained environment-specific credentials.

See which actors are running it and whether you're in range.
12 events from the most recent confirmed update back to the earliest known activity.
The www.ayuthayatech[.]com domain, used as the apparent MeshCentral management endpoint, was moved behind Cloudflare nameservers.
Hunt.io first captured an exposed directory on 92.63.180[.]133:8888 hosted on infrastructure attributed to Bangmod Enterprise. It contained 298 intrusion-related files across 30 subdirectories.
The domain www.ayuthayatech[.]com, later configured as the MeshCentral management server for compromised systems, was registered.
CISA added CVE-2024-21762, a critical FortiOS/FortiProxy SSL-VPN out-of-bounds write flaw, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
The cleanup_target.sh script removed logs, web shells, exploitation files, and other intrusion traces while preserving MeshCentral access and a hidden SUID binary at /usr/local/bin/.rc.
Recovered Jasmine PHP session tokens and systems in the 110.164.131.x range suggested parallel activity against Jasmine infrastructure. The toolkit also contained a Triple T Broadband-related OpenVPN profile with an embedded client certificate for 110.164.129[.]67:443.
Credential-harvesting scripts searched compromised hosts for SSH keys, PHP configuration, database passwords, SNMP strings, and shell history. Separate scripts targeted radius_corp, radiusinfo, and job_radius databases for RADIUS-related authentication data, while password spraying targeted more than 55 internal hosts.
Attackers deployed or prepared MeshCentral agents configured in the TH-3BB device group to connect to www.ayuthayatech[.]com over port 443. A device inventory showed multiple connected endpoints, including agents operating with root privileges.
A Ghostcat exploit tool targeted the internal Pentaho/Tomcat AJP service at 10.11.152.4:8009, and the got63.txt artifact recorded root-level command execution on vm-BCSWILDFLY_M63. The toolkit also included PwnKit, Dirty COW, and hidden SUID-backdoor capabilities.
The toolkit targeted agent.3bb.co[.]th, a CodeIgniter sales-agent portal behind F5 BIG-IP, with session-forgery, brute-force, SQL injection, traversal, SSRF, and request-smuggling attempts. An authenticated response artifact indicated access to internal register_report functionality, while the associated F5 system was probed for known vulnerabilities.
Recovered network configuration showed tooling executed from internal address 10.11.152.63 with the triplet.co.th DNS search domain, indicating an already compromised internal 3BB system.
Recovered tooling indicates attackers used CVE-2024-21762 against the FortiGate 60F SSL-VPN service at mail.3bb.co[.]th:10443. The exploit used heap spraying, malformed chunked requests, and a ROP chain to launch a Node.js reverse shell to 92.63.180[.]133:9443.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.