An alarming cyber attack has been identified within the infrastructure of 3BB, one of Thailand’s prominent broadband providers. According to Hunt.io, a threat intelligence firm, the attacker leveraged the legitimate remote management tool MeshCentral to covertly control internal systems.
Discovery and Infiltration Method
The intrusion was uncovered when researchers at Hunt.io came across an exposed server on the internet, which was left open by the attacker. This server contained the attacker’s tools and an inventory of compromised machines. The discovery was made on June 3, 2026, while the malicious operation was actively underway.
Upon inspection, it was revealed that the attacker’s activities involved using a computer within 3BB’s network to execute commands. A file recovered from the compromised server demonstrated that the attacker had obtained root access to an internal server.
Mechanism of Control and Persistent Access
To maintain control, the attacker deployed MeshCentral, typically utilized by IT teams for remote management. However, in this instance, it was configured as a concealed backdoor. The agents reported back to a control server managed by the attacker, under a device group labeled TH-3BB.
The exploitation of remote-management software like MeshCentral is on the rise, as it often goes unnoticed, blending with regular administrative tasks. The attacker reportedly used a cleanup script to erase logs and other tools while leaving the MeshCentral agent intact to ensure continued access.
Objectives and Broader Implications
The primary aim of the cyber attack was to extract subscriber data from 3BB. Scripts found on the server were designed to copy data from the company’s RADIUS databases, which store customer login credentials. However, evidence of data exfiltration remains unconfirmed.
Additionally, a valid VPN certificate from 3BB’s systems and active login sessions for the Jasmine network were discovered on the server, indicating potential targeting of both networks. Although Jasmine shares infrastructure with 3BB, there was no confirmation of a breach.
Recommendations for Cybersecurity Measures
Organizations using similar systems are advised to patch FortiGate SSL-VPN appliances against CVE-2024-21762, as recommended by Fortinet. It is crucial to identify and remove unauthorized MeshCentral agents and unrecognized management server connections.
Rotating exposed credentials, including SSH keys and database passwords, is essential. Investigating for hidden backdoors like unexpected SUID files or web shells, and preserving logs before cleanup, is strongly advised. The full technical details are available in Hunt.io’s report, providing further guidance.
