Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Nigel Farage says £72m donation are compliant ‘with the law today’

    September 14, 2026

    Top civil servant sacked by Starmer received record £860,000 payout | Civil service

    September 14, 2026

    Trump throws out power plant climate pollution rules

    September 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Nigel Farage says £72m donation are compliant ‘with the law today’
    • Top civil servant sacked by Starmer received record £860,000 payout | Civil service
    • Trump throws out power plant climate pollution rules
    • 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
    • Banks Want More: Trade Groups Demand Stricter Stablecoin Limits in Clarity Act
    • Chemistry textbooks have been getting this wrong for nearly 100 years
    • Against the odds, endangered dolphins survive in Bangladesh’s polluted river
    • Russia’s Attack on a Ukrainian Train Shows Putin Is Growing Bolder
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 14, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 14, 2026Network Security / Cyber Attack

    An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.

    The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker’s own tools and a list of machines already under their control.

    The researchers captured the exposed server on June 3, 2026, while the operation was still live. The tools on it had been run from a computer inside 3BB’s own network, and one recovered file showed the attacker gaining full administrative control, known as root, of an internal server.

    To maintain that access, the attacker installed MeshCentral, a free tool that IT teams typically use to manage computers remotely. The recovered settings show it was configured as a hidden backdoor, with the agents reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB.

    Attackers increasingly abuse this kind of remote-management software because it is trusted and its activity blends in with routine administration.

    Cybersecurity

    A device list recovered from the server named the machines enrolled in the attacker’s MeshCentral setup. Several were connected and running with root privileges when the list was made, which the researchers said showed the attacker held active administrative control at that point.

    A separate cleanup script was written to erase logs and delete the attacker’s other tools while deliberately leaving the MeshCentral agent in place so that the access would survive.

    Inside the network, the attacker worked to widen their access. Recovered scripts sprayed passwords against more than 55 internal computers over SSH, probed 3BB’s internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords, database logins, and SSH keys. Other scripts could plant web shells, hidden pages that run an attacker’s commands, and add SSH keys as backup ways back in.

    Hunt.io said the attacker’s main goal was 3BB’s subscriber data. Scripts on the server were built to copy out the company’s RADIUS databases, the systems that store the login credentials broadband customers use to get online. The evidence shows those databases were targeted, not that any data was taken.

    The same server pointed to a second target. It held a valid VPN certificate from 3BB’s own systems and active login sessions for services on the Jasmine network, a company 3BB was once part of and still shares infrastructure with. Hunt.io said this suggested the attacker was working against both, though it did not confirm that Jasmine itself had been breached.

    How the attacker initially gained access to 3BB is not established. The server held a full toolkit aimed at a 3BB FortiGate SSL-VPN gateway, the remote-access box at mail.3bb.co[.]th, including a complete exploit for CVE-2024-21762, a serious 2024 Fortinet flaw that lets an attacker run code on the device without logging in. The targeted gateway was running a firmware version affected by the flaw.

    But nothing Hunt.io recovered shows the exploit actually worked, or that it was how the attacker got in. The FortiGate tooling was the most developed part of the kit, yet it points to the attacker’s capability and intent, not a confirmed break-in through that device.

    The attacker has since closed the exposed directory. Whether they still have access inside 3BB is not known, because the evidence describes the intrusion as it stood in early June, not today.

    Cybersecurity

    The researchers said they notified the affected companies and the relevant national response team about their findings before publishing.

    What Defenders Should Do

    The recovered toolkit points to a clear set of steps for organizations running similar edge devices and authentication systems:

    • Patch or confirm that FortiGate SSL-VPN appliances are fixed against CVE-2024-21762. Fortinet’s advisory says that if you cannot patch at once, you should turn off SSL-VPN, and that turning off web mode alone is not a valid workaround.
    • Check for MeshCentral agents you did not install, and for connections to management servers you do not recognize.
    • Rotate credentials that may have been exposed, including SSH keys, database and RADIUS passwords, VPN certificates, and application secrets. Patching does not remove an agent that is already installed or reset a password that has already been copied.
    • Hunt for hidden ways back in, such as unexpected SUID files, web shells, changed SSH keys, and newly added remote-management software.
    • Preserve logs and evidence before cleaning up, because the attacker’s own script was built to erase them.

    Key indicators from the report, shown in defanged form:

    • IP address: 92.63.180[.]133, the attacker’s server (port 8888 held the open directory, port 9443 received the exploit callback)
    • Domain: www.ayuthayatech[.]com, the MeshCentral control server
    • MeshCentral group: TH-3BB
    • Persistence paths: /usr/local/bin/.rc, a hidden backdoor, and /usr/local/mesh_services/meshagent/
    • Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal)

    The full list of indicators, along with the technical details, is in Hunt.io’s report.

    3BB access attacker Backdoor Credentials MeshCentral Root Subscriber targeted
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records

    New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

    New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

    Why Patch Automation Needs Brakes, Not Just an Accelerator

    Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Nigel Farage says £72m donation are compliant ‘with the law today’

    September 14, 2026

    Top civil servant sacked by Starmer received record £860,000 payout | Civil service

    September 14, 2026

    Trump throws out power plant climate pollution rules

    September 14, 2026

    3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    September 14, 2026
    Latest Posts

    What Is an Air-Gapped Bitcoin Wallet? Why the Coldcard Exploit Changes the Conversation About Offline Security

    August 3, 2026

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    August 3, 2026

    T-Mobile will give you the new Samsung Galaxy Z Flip for practically nothing if you preorder now

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Nigel Farage says £72m donation are compliant ‘with the law today’

    September 14, 2026

    Top civil servant sacked by Starmer received record £860,000 payout | Civil service

    September 14, 2026

    Trump throws out power plant climate pollution rules

    September 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.