BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Attacker infiltrates 3BB network via MeshCentral backdoor

  • An attacker infiltrated 3BB, a major Thai broadband provider, using the legitimate remote management tool MeshCentral as a hidden backdoor.
  • The attacker targeted 3BB‘s RADIUS databases containing broadband subscriber credentials, though data exfiltration was not confirmed.
  • A recovered toolkit included an exploit for the Fortinet flaw CVE-2024-21762, aimed at the company’s SSL-VPN gateway, but proof of successful exploitation is missing.
  • Researchers found evidence the attacker also had access to the Jasmine network, a former parent company, via a valid VPN certificate and active login sessions.

A sophisticated attacker infiltrated the network of 3BB, one of Thailand’s largest broadband providers, maintaining remote access through a legitimate management tool called MeshCentral, according to threat intelligence firm Hunt.io. Researchers discovered the intrusion on June 3, 2026, after spotting an exposed server holding the attacker’s tools and a list of compromised machines.

- Advertisement -

The attacker operated from inside 3BB‘s network and used MeshCentral to maintain root-level administrative control over internal servers. Attackers increasingly abuse such remote-management software because its activity blends with routine administration. A cleanup script on the server was designed to erase other tools while deliberately preserving the MeshCentral agent, ensuring persistent access.

The attacker’s primary goal appeared to be 3BB‘s subscriber data. Recovered scripts targeted the company’s RADIUS databases, which store broadband login credentials, though Hunt.io found no evidence data was actually taken. Inside the network, the attacker also probed the internal sales portal, sprayed passwords against over 55 internal machines, and searched for stored credentials and SSH keys.

The compromised server held an exploit for CVE-2024-21762, a serious Fortinet flaw from 2024 that allows code execution without authentication. The tooling was aimed at 3BB‘s FortiGate SSL-VPN gateway, but nothing recovered confirmed the exploit was successful. The same server also contained a valid VPN certificate from 3BB and active login sessions for services on the Jasmine network, suggesting the attacker worked against both companies, though a breach of Jasmine itself was not confirmed.

Hunt.io notified the affected companies and the relevant national response team before publishing its findings. Key indicators include the attacker’s IP address (92.63.180[.]133), the domain www.ayuthayatech[.]com acting as the MeshCentral control server, and specific persistence paths within 3BB‘s systems. The full technical details are available in Hunt.io’s report.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw...

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Qureshi Slams Drake’s ‘Bunker Mode’ as Crypto Doomerism

Dragonfly managing partner Haseeb Qureshi called Ethereum researcher Justin Drake’s “bunker mode” warning “cryptographic...

CISA Adds 5 Flax Typhoon Exploited Flaws to KEV Catalog

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after China-linked threat actor...

Must Read

5 Best Hacking eBooks for Beginners

In this article we present the 5 Best Hacking eBooks for beginners as ranked by our editorial teamWelcome to the world of hacking, where...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading