Threat-intelligence researchers at Hunt.io have documented an intrusion affecting a Thai broadband provider in which attackers targeted a FortiGate SSL VPN and later deployed the MeshCentral remote-management platform. SecurityWeek independently summarized the research on September 15.
The observed infrastructure hosted reconnaissance scripts, vulnerability probes, brute-force utilities and privilege-escalation tools. Hunt.io’s account links the activity to exploitation of a Fortinet flaw, but attribution to a named threat group was not established in the public reporting.
Remote-management software can have legitimate administrative uses, which makes context essential. In this case, its placement alongside offensive tooling and the intrusion path made it part of the incident evidence rather than proof that the software itself was malicious.
Why it matters
Broadband providers sit at the intersection of public communications and critical infrastructure. Internet-facing security appliances require rapid patching, while remote-administration activity needs monitoring that can distinguish expected maintenance from unauthorized persistence.
For wider context, see SectechMedia’s related technical coverage.
