Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
3BB Network Breach: MeshCentral Backdoor Exploited

3BB Network Breach: MeshCentral Backdoor Exploited

Posted on September 14, 2026 By CWS

An alarming cyber attack has been identified within the infrastructure of 3BB, one of Thailand’s prominent broadband providers. According to Hunt.io, a threat intelligence firm, the attacker leveraged the legitimate remote management tool MeshCentral to covertly control internal systems.

Discovery and Infiltration Method

The intrusion was uncovered when researchers at Hunt.io came across an exposed server on the internet, which was left open by the attacker. This server contained the attacker’s tools and an inventory of compromised machines. The discovery was made on June 3, 2026, while the malicious operation was actively underway.

Upon inspection, it was revealed that the attacker’s activities involved using a computer within 3BB’s network to execute commands. A file recovered from the compromised server demonstrated that the attacker had obtained root access to an internal server.

Mechanism of Control and Persistent Access

To maintain control, the attacker deployed MeshCentral, typically utilized by IT teams for remote management. However, in this instance, it was configured as a concealed backdoor. The agents reported back to a control server managed by the attacker, under a device group labeled TH-3BB.

The exploitation of remote-management software like MeshCentral is on the rise, as it often goes unnoticed, blending with regular administrative tasks. The attacker reportedly used a cleanup script to erase logs and other tools while leaving the MeshCentral agent intact to ensure continued access.

Objectives and Broader Implications

The primary aim of the cyber attack was to extract subscriber data from 3BB. Scripts found on the server were designed to copy data from the company’s RADIUS databases, which store customer login credentials. However, evidence of data exfiltration remains unconfirmed.

Additionally, a valid VPN certificate from 3BB’s systems and active login sessions for the Jasmine network were discovered on the server, indicating potential targeting of both networks. Although Jasmine shares infrastructure with 3BB, there was no confirmation of a breach.

Recommendations for Cybersecurity Measures

Organizations using similar systems are advised to patch FortiGate SSL-VPN appliances against CVE-2024-21762, as recommended by Fortinet. It is crucial to identify and remove unauthorized MeshCentral agents and unrecognized management server connections.

Rotating exposed credentials, including SSH keys and database passwords, is essential. Investigating for hidden backdoors like unexpected SUID files or web shells, and preserving logs before cleanup, is strongly advised. The full technical details are available in Hunt.io’s report, providing further guidance.

The Hacker News Tags:3BB, broadband provider, CVE-2024-21762, cyber attack, Cybersecurity, data security, Fortigate, Hunt.io, MeshCentral, network breach, remote access, subscriber credentials, Thailand, VPN

Post navigation

Previous Post: Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
Next Post: UK Introduces Passkeys for 23 Million GOV.UK Users

Related Posts

Exploitation of TrueConf Flaw Targets Southeast Asian Governments Exploitation of TrueConf Flaw Targets Southeast Asian Governments The Hacker News
N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto The Hacker News
Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More The Hacker News
How To Automate Ticket Creation, Device Identification and Threat Triage With Tines How To Automate Ticket Creation, Device Identification and Threat Triage With Tines The Hacker News
Critical Cisco SD-WAN Vulnerability Exploited Since 2023 Critical Cisco SD-WAN Vulnerability Exploited Since 2023 The Hacker News
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark