Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
3BB Network Breach: MeshCentral Backdoor Exploited

3BB Network Breach: MeshCentral Backdoor Exploited

Posted on September 14, 2026 By CWS

An alarming cyber attack has been identified within the infrastructure of 3BB, one of Thailand’s prominent broadband providers. According to Hunt.io, a threat intelligence firm, the attacker leveraged the legitimate remote management tool MeshCentral to covertly control internal systems.

Discovery and Infiltration Method

The intrusion was uncovered when researchers at Hunt.io came across an exposed server on the internet, which was left open by the attacker. This server contained the attacker’s tools and an inventory of compromised machines. The discovery was made on June 3, 2026, while the malicious operation was actively underway.

Upon inspection, it was revealed that the attacker’s activities involved using a computer within 3BB’s network to execute commands. A file recovered from the compromised server demonstrated that the attacker had obtained root access to an internal server.

Mechanism of Control and Persistent Access

To maintain control, the attacker deployed MeshCentral, typically utilized by IT teams for remote management. However, in this instance, it was configured as a concealed backdoor. The agents reported back to a control server managed by the attacker, under a device group labeled TH-3BB.

The exploitation of remote-management software like MeshCentral is on the rise, as it often goes unnoticed, blending with regular administrative tasks. The attacker reportedly used a cleanup script to erase logs and other tools while leaving the MeshCentral agent intact to ensure continued access.

Objectives and Broader Implications

The primary aim of the cyber attack was to extract subscriber data from 3BB. Scripts found on the server were designed to copy data from the company’s RADIUS databases, which store customer login credentials. However, evidence of data exfiltration remains unconfirmed.

Additionally, a valid VPN certificate from 3BB’s systems and active login sessions for the Jasmine network were discovered on the server, indicating potential targeting of both networks. Although Jasmine shares infrastructure with 3BB, there was no confirmation of a breach.

Recommendations for Cybersecurity Measures

Organizations using similar systems are advised to patch FortiGate SSL-VPN appliances against CVE-2024-21762, as recommended by Fortinet. It is crucial to identify and remove unauthorized MeshCentral agents and unrecognized management server connections.

Rotating exposed credentials, including SSH keys and database passwords, is essential. Investigating for hidden backdoors like unexpected SUID files or web shells, and preserving logs before cleanup, is strongly advised. The full technical details are available in Hunt.io’s report, providing further guidance.

The Hacker News Tags:3BB, broadband provider, CVE-2024-21762, cyber attack, Cybersecurity, data security, Fortigate, Hunt.io, MeshCentral, network breach, remote access, subscriber credentials, Thailand, VPN

Post navigation

Previous Post: Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
Next Post: UK Introduces Passkeys for 23 Million GOV.UK Users

Related Posts

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse The Hacker News
Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months The Hacker News
Plex Urges Immediate Update for Security Patches Plex Urges Immediate Update for Security Patches The Hacker News
The Emerging Threat of Mythos in Open Source The Emerging Threat of Mythos in Open Source The Hacker News
Hackers Exploit Critical WordPress Theme Flaw to Hijack Sites via Remote Plugin Install Hackers Exploit Critical WordPress Theme Flaw to Hijack Sites via Remote Plugin Install The Hacker News
CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark