[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6isMSMcGSrzt2eTu8gtdUUY-Ad4w5RAYsPnGNbVs7bA":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"3dc9a09e-a10c-4eed-a50e-cf09bdc58f8c","3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials","3bb-attacker-used-meshcentral-backdoor-for-root-access-targeted-subscriber-crede-2e4ea2","An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of","An attacker infiltrated 3BB, a major Thai broadband provider, using MeshCentral as a backdoor for root access. Threat intelligence firm Hunt.io discovered the intrusion by analyzing an exposed server containing the attacker's tools. The attacker aimed to steal subscriber credentials from RADIUS databases and also targeted the Jasmine network, potentially exploiting a FortiGate SSL-VPN vulnerability.","Attacker used MeshCentral backdoor for root access at 3BB, targeting subscriber credentials.","3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials Swati KhandelwalSep 14, 2026Network Security \u002F Cyber Attack An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of machines already under their control. The researchers captured the exposed server on June 3, 2026, while the operation was still live. The tools on it had been run from a computer inside 3BB's own network, and one recovered file showed the attacker gaining full administrative control, known as root, of an internal server. To maintain that access, the attacker installed MeshCentral, a free tool that IT teams typically use to manage computers remotely. The recovered settings show it was configured as a hidden backdoor, with the agents reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB. Attackers increasingly abuse this kind of remote-management software because it is trusted and its activity blends in with routine administration. A device list recovered from the server named the machines enrolled in the attacker's MeshCentral setup. Several were connected and running with root privileges when the list was made, which the researchers said showed the attacker held active administrative control at that point. A separate cleanup script was written to erase logs and delete the attacker's other tools while deliberately leaving the MeshCentral agent in place so that the access would survive. Inside the network, the attacker worked to widen their access. Recovered scripts sprayed passwords against more than 55 internal computers over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords, database logins, and SSH keys. Other scripts could plant web shells, hidden pages that run an attacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Scripts on the server were built to copy out the company's RADIUS databases, the systems that store the login credentials broadband customers use to get online. The evidence shows those databases were targeted, not that any data was taken. The same server pointed to a second target. It held a valid VPN certificate from 3BB's own systems and active login sessions for services on the Jasmine network, a company 3BB was once part of and still shares infrastructure with. Hunt.io said this suggested the attacker was working against both, though it did not confirm that Jasmine itself had been breached. How the attacker initially gained access to 3BB is not established. The server held a full toolkit aimed at a 3BB FortiGate SSL-VPN gateway, the remote-access box at mail.3bb.co[.]th, including a complete exploit for CVE-2024-21762, a serious 2024 Fortinet flaw that lets an attacker run code on the device without logging in. The targeted gateway was running a firmware version affected by the flaw. But nothing Hunt.io recovered shows the exploit actually worked, or that it was how the attacker got in. The FortiGate tooling was the most developed part of the kit, yet it points to the attacker's capability and intent, not a confirmed break-in through that device. The attacker has since closed the exposed directory. Whether they still have access inside 3BB is not known, because the evidence describes the intrusion as it stood in early June, not today. The researchers said they notified the affected companies and the relevant national response team about their findings before publishing. What Defenders Should Do The recovered toolkit points to a clear set of steps for organizations running similar edge devices and authentication systems: Patch or confirm that FortiGate SSL-VPN appliances are fixed against CVE-2024-21762. Fortinet's advisory says that if you cannot patch at once, you should turn off SSL-VPN, and that turning off web mode alone is not a valid workaround. Check for MeshCentral agents you did not install, and for connections to management servers you do not recognize. Rotate credentials that may have been exposed, including SSH keys, database and RADIUS passwords, VPN certificates, and application secrets. Patching does not remove an agent that is already installed or reset a password that has already been copied. Hunt for hidden ways back in, such as unexpected SUID files, web shells, changed SSH keys, and newly added remote-management software. Preserve logs and evidence before cleaning up, because the attacker's own script was built to erase them. Key indicators from the report, shown in defanged form: IP address: 92.63.180[.]133, the attacker's server (port 8888 held the open directory, port 9443 received the exploit callback) Domain: www.ayuthayatech[.]com, the MeshCentral control server MeshCentral group: TH-3BB Persistence paths: \u002Fusr\u002Flocal\u002Fbin\u002F.rc, a hidden backdoor, and \u002Fusr\u002Flocal\u002Fmesh_services\u002Fmeshagent\u002F Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along with the technical details, is in Hunt.io's report. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cyber Attack, Fortinet, network security, Vulnerability ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries Why Are So Many Security Professionals Keeping Breaches Quiet? The Economics of Dwell Time and Why AI Native SIEM Changes the Equation ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002F3bb-attacker-used-meshcentral-backdoor.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEg9khzZCrFkNfQ1fOYHT8A4LJrIsfc52ppe6xZffdUrfRacqTVQ76P0VPDZhqC2UfKM32jdbEiQfaCZDbrV2F0_dssOM8V8nT3ZZYvwhflLdfEhJhdNa0-UntK9XHkFJ4R5RthFMOM2X5kDZxUKW1RnRLmmQ0xLh5foMldMZovB0ZPdafoRf9cEb_w9Hwk\u002Fs1600\u002F3bb.jpg","2026-09-14T18:01:49+00:00","2026-09-14T20:00:07.025729+00:00",8,[18,21,24,26,28],{"name":19,"type":20},"3BB","vendor",{"name":22,"type":23},"MeshCentral","product",{"name":25,"type":20},"Hunt.io",{"name":27,"type":20},"Fortinet",{"name":29,"type":23},"FortiGate SSL-VPN","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":30,"icon":32,"name":33,"slug":34},null,"Threat Intelligence","threat-intelligence",[36,41,46,51],{"category":37},{"id":38,"icon":32,"name":39,"slug":40},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":42},{"id":43,"icon":32,"name":44,"slug":45},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":47},{"id":48,"icon":32,"name":49,"slug":50},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":52},{"id":30,"icon":32,"name":33,"slug":34},[54,58],{"type":55,"value":56,"context":57},"domain","www.ayuthayatech[.]com","Attacker's MeshCentral control server",{"type":59,"value":60,"context":61},"cve","CVE-2024-21762","Fortinet flaw potentially used by attacker"]