< Back to all clusters
[TECHNOLOGY] · Thailand · 2 sources

started · updated

3BB broadband provider targeted in MeshCentral backdoor attack

An attacker infiltrated 3BB, a major Thai broadband provider, by using the legitimate remote management tool MeshCentral as a hidden backdoor to maintain root-level administrative control over internal servers. The intrusion was discovered on June 3, 2026, after researchers identified an exposed server containing the attacker’s toolkit and a list of compromised machines.

The attacker utilized the MeshCentral agent to blend in with routine IT administration. A specialized cleanup script was designed to delete logs and other tools while deliberately preserving the MeshCentral agent to ensure persistent access. Once inside, the attacker performed password spraying against more than 55 internal machines via SSH, probed internal sales portals, and searched for stored credentials and SSH keys.

The primary target appeared to be 3BB’s RADIUS databases, which contain broadband subscriber credentials, though no evidence of data exfiltration has been confirmed. Additionally, the attacker possessed an exploit for the Fortinet vulnerability CVE-2024-21762, aimed at the company’s SSL-VPN gateway. Evidence also suggested access to the Jasmine network, a former parent company, through valid VPN certificates and active login sessions.

Entities

3BB · Fortinet · Hunt.io · Jasmine · MeshCentral