AI Security AI安全 4h ago Updated 2h ago 更新于 2小时前 40

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials 3BB攻击者利用MeshCentral后门获取Root权限,针对用户凭据

An attacker operated inside 3BB's network using MeshCentral, a legitimate remote management tool, as a hidden backdoor to maintain root access to internal servers The intrusion was discovered when Hunt.io captured an exposed attacker-controlled server on June 3, 2026, revealing tools, device lists, and persistence mechanisms The attacker's primary objective was exfiltrating 3BB's RADIUS databases containing subscriber credentials, with evidence of targeting both 3BB and the Jasmine network A com 攻击者利用MeshCentral合法远程管理工具作为隐藏后门,在泰国宽带提供商3BB网络内部维持root级访问权限 攻击目标明确指向RADIUS数据库中的宽带用户凭证,同时持有Jasmine网络VPN证书和活跃会话 攻击者准备了完整的CVE-2024-21762漏洞利用工具包针对FortiGate SSL-VPN网关,但入侵途径尚未确认 攻击者使用清理脚本删除日志和其他工具,但故意保留MeshCentral agent以确保持久化访问

58
Hot 热度
62
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • An attacker operated inside 3BB's network using MeshCentral, a legitimate remote management tool, as a hidden backdoor to maintain root access to internal servers
  • The intrusion was discovered when Hunt.io captured an exposed attacker-controlled server on June 3, 2026, revealing tools, device lists, and persistence mechanisms
  • The attacker's primary objective was exfiltrating 3BB's RADIUS databases containing subscriber credentials, with evidence of targeting both 3BB and the Jasmine network
  • A complete exploit toolkit for CVE-2024-21762 (Fortinet SSL-VPN vulnerability) was found, though it was not confirmed whether this was the initial access vector
  • The attacker employed sophisticated anti-forensics, including a cleanup script that erased logs while deliberately preserving the MeshCentral agent for persistent access

Why It Matters

This incident exemplifies the growing trend of attackers abusing legitimate remote management tools to blend malicious activity with routine administration, making detection significantly harder for security teams. It also highlights the critical importance of patching known vulnerabilities like CVE-2024-21762 in edge devices, as unpatched SSL-VPN gateways remain a prime entry point for sophisticated threat actors targeting telecommunications infrastructure.

Technical Details

  • MeshCentral Backdoor: The attacker installed MeshCentral agents on compromised machines, configuring them to report to a control server at www.ayuthayatech[.]com under device group "TH-3BB", with several agents running under root privileges
  • Persistence Mechanisms: Hidden backdoor at /usr/local/bin/.rc and MeshCentral agent at /usr/local/mesh_services/meshagent/, with a cleanup script designed to erase logs and delete tools while preserving the MeshCentral agent for continued access
  • Lateral Movement: Password spraying against 55+ internal computers via SSH, probing of internal sales portal at agent.3bb.co[.]th, and scripts to plant web shells and add SSH keys as backup access methods
  • Targeted Data: Scripts were specifically built to copy RADIUS databases storing broadband customer login credentials; a valid VPN certificate and active sessions for the Jasmine network were also found on the attacker's server
  • Exploit Toolkit: Complete exploit package for CVE-2024-21762 targeting FortiGate SSL-VPN at mail.3bb.co[.]th, though it remains unconfirmed whether this vulnerability was successfully exploited for initial access

Industry Insight

  • Organizations should immediately audit all remote management tools (especially MeshCentral, TeamViewer, AnyDesk) for unauthorized installations and connections to unrecognized control servers, as attackers increasingly weaponize legitimate software for persistence
  • Patch management for edge devices, particularly SSL-VPN gateways, must be treated as critical; CVE-2024-21762 demonstrates how unpatched vulnerabilities in remote access infrastructure can enable deep network compromise
  • Incident response playbooks should account for anti-forensics tactics like log deletion; preserving evidence before cleanup is essential, and credential rotation must be prioritized over simple patching since copied passwords and installed agents persist even after vulnerability remediation

TL;DR

  • 攻击者利用MeshCentral合法远程管理工具作为隐藏后门,在泰国宽带提供商3BB网络内部维持root级访问权限
  • 攻击目标明确指向RADIUS数据库中的宽带用户凭证,同时持有Jasmine网络VPN证书和活跃会话
  • 攻击者准备了完整的CVE-2024-21762漏洞利用工具包针对FortiGate SSL-VPN网关,但入侵途径尚未确认
  • 攻击者使用清理脚本删除日志和其他工具,但故意保留MeshCentral agent以确保持久化访问

为什么值得看

这篇文章揭示了攻击者滥用合法IT管理工具的典型战术,展示了现代网络攻击中"信任工具"被武器化的趋势。对安全从业者而言,提供了具体的IoC指标和防御建议,有助于识别类似攻击模式。

技术解析

  • 攻击者使用MeshCentral作为持久化后门,配置为隐藏回连至www.ayuthayatech[.]com控制服务器,设备组命名为TH-3BB
  • 攻击者通过SSH密码喷洒攻击55台以上内部计算机,探测内部销售门户agent.3bb.co.th,并搜索已妥协机器上的存储密码、数据库登录凭证和SSH密钥
  • 攻击者准备了针对mail.3bb.co.th的FortiGate SSL-VPN网关的完整工具包,包含CVE-2024-21762漏洞利用代码,该漏洞允许未认证远程代码执行
  • 攻击者使用清理脚本删除日志和其他工具,但故意保留MeshCentral agent以确保访问持久性,同时部署web shells和添加SSH密钥作为备用回传途径
  • 主要目标为3BB的RADIUS数据库(存储宽带客户登录凭证),同时持有3BB的VPN证书和Jasmine网络的活跃登录会话

行业启示

  • 合法远程管理工具(如MeshCentral)正被攻击者广泛滥用,因其受信任且活动与常规管理操作难以区分,组织需加强对这类工具的监控和异常检测
  • 边缘设备(如SSL-VPN网关)的漏洞利用仍是攻击者的重要入口,及时修补CVE-2024-21762等严重漏洞至关重要,无法立即修补时应关闭SSL-VPN功能
  • 攻击者采用"清理痕迹但保留后门"的策略,组织在响应事件时应先保留日志和证据,再执行清理操作,同时全面轮换可能暴露的凭证

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全