Network Security

Attacker maintained remote control of 3BB network using MeshCentral

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of machines already under their control, with further coverage provided by The Hacker News.

Researchers captured the exposed server on June 3, 2026, while the operation was still live. The attacker gained full administrative control of an internal server and installed MeshCentral as a hidden backdoor, with agents reporting to a control server. Attackers increasingly abuse such remote-management software because it is trusted and its activity blends in with routine administration. A cleanup script was used to erase logs and delete other tools, leaving the MeshCentral agent in place for persistence. The attacker also worked to widen their access by spraying passwords, probing internal portals, and searching for stored credentials.

The primary goal appeared to be 3BB's subscriber data, specifically RADIUS databases, though evidence suggests the data was targeted, not exfiltrated. The same server also indicated a secondary target on the Jasmine network, suggesting a broader campaign. While a FortiGate SSL-VPN gateway exploit (CVE-2024-21762) was found in the attacker's toolkit, it's unconfirmed if this was the initial entry point. The attacker has since closed the exposed directory, and their current access level is unknown.

Source: The Hacker News

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds