Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2831+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. 3BB Attacker Used MeshCentral Backdoor for Root Access to Subscriber Data
3BB Attacker Used MeshCentral Backdoor for Root Access to Subscriber Data
NEWS

3BB Attacker Used MeshCentral Backdoor for Root Access to Subscriber Data

An intruder inside Thai broadband provider 3BB used MeshCentral as a hidden backdoor, gaining root access to 55+ machines to target RADIUS...

Dylan H.

News Desk

September 14, 2026
3 min read

Trusted Tooling as a Backdoor

An attacker maintained unauthorized access inside 3BB, one of Thailand's largest broadband providers, by installing MeshCentral — a legitimate open-source remote management tool — and quietly configuring it as a hidden backdoor. Threat intelligence firm Hunt.io discovered the intrusion after finding an exposed control server still active as of June 2026.


How the Backdoor Was Configured

The attacker deployed MeshCentral on internal 3BB servers and pointed it at a command-and-control domain, www.ayuthayatech[.]com, under a device group labeled "TH-3BB." As Hunt.io noted, attackers increasingly favor legitimate remote-management software for persistence precisely because its activity blends in with routine IT administration — it doesn't trigger the same alarms as a custom malware implant.


Scope of the Compromise

Recovered device enrollment lists showed multiple machines connected to the backdoor with root-level privileges, indicating active administrative control rather than passive access. The attacker achieved full system access to at least one internal server and expanded to 55+ compromised machines using password-spray attacks against SSH.


The Target: Subscriber Credentials

The attacker's primary objective appears to have been subscriber authentication data. Scripts recovered from the environment were built to extract RADIUS databases — the systems that store broadband customer login credentials. Hunt.io found evidence of targeting these databases, though no confirmation that data was successfully exfiltrated.


A Possible Entry Point

While the attacker possessed a complete exploit toolkit for CVE-2024-21762, a Fortinet FortiGate SSL-VPN vulnerability, Hunt.io found no conclusive proof this was the actual entry vector — only that the targeted VPN gateway was running firmware vulnerable to that flaw.


Discovery and Response

Hunt.io notified 3BB and relevant national incident response teams before publishing its findings. The attacker has since closed the exposed control-panel directory that enabled discovery, and the current state of access to 3BB's network is unknown.


Defender Recommendations

  1. Patch CVE-2024-21762 on all FortiGate SSL-VPN appliances immediately if not already done
  2. Hunt for unauthorized MeshCentral agents or other RMM tools not part of your sanctioned toolset
  3. Rotate all potentially exposed credentials, especially RADIUS and administrative accounts
  4. Search for additional persistence — web shells, unauthorized SSH keys, SUID binaries
  5. Preserve forensic logs before any cleanup or remediation activity begins

References

  • The Hacker News — 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

Related Reading

  • Hackers Target Exposed Vite Dev Servers to Steal AWS, Azure Secrets
  • Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks
#Threat Intelligence#MeshCentral#RMM Abuse#Telecom Security#Thailand

Related Articles

Hermes AI Agent Used to Automate Attack on Thai Finance Ministry

A threat actor deployed the open-source Hermes AI agent in unattended 'YOLO' mode to autonomously conduct post-exploitation against Thailand's Ministry of...

5 min read

Hackers Exploit Cisco SD-WAN Zero-Day for Root Access at Telecom Provider

Mandiant has detailed an incident in which threat actors exploited a Cisco SD-WAN zero-day vulnerability to gain the highest possible access level at a...

5 min read

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A maximum-severity zero-day vulnerability in Metabase — the widely used open-source business analytics platform — allows remote attackers to gain administrator access without authentication, potentially exposing the platform's downstream users and connected data sources.

3 min read
Back to all News