3BB Attacker Exploits MeshCentral Backdoor for Root Access, Compromising Subscriber Credentials

Cyber Intrusion Discovered at Major Thai Broadband Provider 3BB

In a significant cybersecurity incident, an attacker has infiltrated the network of 3BB, one of Thailand’s largest broadband service providers, maintaining remote access to internal systems through an authorized management tool known as MeshCentral. The breach was uncovered by threat intelligence firm Hunt.io, which identified the illicit activity by inspecting a publicly accessible server that contained the attacker’s toolkit and a comprehensive roster of compromised machines.

On June 3, 2026, researchers from Hunt.io detected the active intrusion while examining the exposed server. This server had been leveraged to execute the attack from within 3BB’s own infrastructure. Analysis of the recovered files revealed that the attacker had established full administrative access, commonly referred to as “root” access, over one of the organization’s internal servers. The use of MeshCentral, typically employed by IT teams for legitimate remote management, enabled the attacker to configure a covert backdoor that communicated with a command server located at www.ayuthayatech[.]com, categorized under a device group labeled TH-3BB.

The use of legitimate remote-management software for malicious purposes is increasingly common among cyber adversaries, as it allows their activities to blend seamlessly with routine administrative tasks, thus reducing scrutiny. Additionally, Hunt.io obtained a device list revealing that multiple machines were not only enrolled in the attacker’s MeshCentral setup but were also actively running with root privileges at the time of the discovery, highlighting the attacker’s robust administrative presence within the network.

As part of maintaining persistent access, the attacker executed a cleanup script designed to erase logs and eliminate various tools while deliberately preserving the MeshCentral agent to ensure continued access. The forensic evidence indicates that once inside the network, the attacker sought to expand their foothold. This was accomplished by employing scripts that targeted over 55 internal computers via SSH, probing 3BB’s internal sales portal, and searching for stored passwords, database logins, and SSH keys.

Hunt.io asserts that the primary objective of the attack was to access subscriber data, as the scripts retrieved from the server were specifically designed to extract the company’s RADIUS databases, which house customer login credentials for broadband access. While these databases were targeted, there is no conclusive evidence to suggest that any data was successfully extracted.

The compromised server also revealed a second target, containing a valid VPN certificate from 3BB’s infrastructure as well as active login sessions associated with the Jasmine network, a previously linked entity. Although it is suggested that the attacker was aiming at both organizations, definitive proof of a breach at Jasmine remains unconfirmed.

The precise method of initial access for the attacker remains undetermined. However, Hunt.io’s assessment uncovered a full toolkit aimed at exploiting a FortiGate SSL-VPN gateway associated with 3BB, specifically targeting a vulnerability identified as CVE-2024-21762— a critical Fortinet flaw enabling unauthorized code execution. While the toolkit exhibits well-developed capabilities, it does not confirm that this was the exact vector for the attack.

Currently, the status of the attacker’s access is uncertain as the exposed directory has been closed, leaving ambiguity regarding whether they still maintain a presence within 3BB’s network.

This incident underscores the need for vigilance and proactive measures in cybersecurity. Companies operating similar edge devices and authentication systems should take proactive steps to mitigate potential risks. Hunt.io has reported their findings to the affected organizations and relevant national cybersecurity response teams, reiterating the importance of fortifying defenses against such sophisticated intrusions.

In light of this breach, businesses must stay apprised of the evolving landscape of threat tactics and ensure they are implementing rigorous security protocols to safeguard against such incidents. The implications of these vulnerabilities extend beyond immediate concerns, as unauthorized access to sensitive data can have far-reaching consequences for any organization.

Source link