3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker operated inside 3BB's network using MeshCentral, a legitimate remote management tool, as a hidden backdoor to maintain root access to internal servers The intrusion was discovered when Hunt.io captured an exposed attacker-controlled server on June 3, 2026, revealing tools, device lists, and persistence mechanisms The attacker's primary objective was exfiltrating 3BB's RADIUS databases containing subscriber credentials, with evidence of targeting both 3BB and the Jasmine network A com
Analysis
TL;DR
- An attacker operated inside 3BB's network using MeshCentral, a legitimate remote management tool, as a hidden backdoor to maintain root access to internal servers
- The intrusion was discovered when Hunt.io captured an exposed attacker-controlled server on June 3, 2026, revealing tools, device lists, and persistence mechanisms
- The attacker's primary objective was exfiltrating 3BB's RADIUS databases containing subscriber credentials, with evidence of targeting both 3BB and the Jasmine network
- A complete exploit toolkit for CVE-2024-21762 (Fortinet SSL-VPN vulnerability) was found, though it was not confirmed whether this was the initial access vector
- The attacker employed sophisticated anti-forensics, including a cleanup script that erased logs while deliberately preserving the MeshCentral agent for persistent access
Why It Matters
This incident exemplifies the growing trend of attackers abusing legitimate remote management tools to blend malicious activity with routine administration, making detection significantly harder for security teams. It also highlights the critical importance of patching known vulnerabilities like CVE-2024-21762 in edge devices, as unpatched SSL-VPN gateways remain a prime entry point for sophisticated threat actors targeting telecommunications infrastructure.
Technical Details
- MeshCentral Backdoor: The attacker installed MeshCentral agents on compromised machines, configuring them to report to a control server at www.ayuthayatech[.]com under device group "TH-3BB", with several agents running under root privileges
- Persistence Mechanisms: Hidden backdoor at
/usr/local/bin/.rcand MeshCentral agent at/usr/local/mesh_services/meshagent/, with a cleanup script designed to erase logs and delete tools while preserving the MeshCentral agent for continued access - Lateral Movement: Password spraying against 55+ internal computers via SSH, probing of internal sales portal at agent.3bb.co[.]th, and scripts to plant web shells and add SSH keys as backup access methods
- Targeted Data: Scripts were specifically built to copy RADIUS databases storing broadband customer login credentials; a valid VPN certificate and active sessions for the Jasmine network were also found on the attacker's server
- Exploit Toolkit: Complete exploit package for CVE-2024-21762 targeting FortiGate SSL-VPN at mail.3bb.co[.]th, though it remains unconfirmed whether this vulnerability was successfully exploited for initial access
Industry Insight
- Organizations should immediately audit all remote management tools (especially MeshCentral, TeamViewer, AnyDesk) for unauthorized installations and connections to unrecognized control servers, as attackers increasingly weaponize legitimate software for persistence
- Patch management for edge devices, particularly SSL-VPN gateways, must be treated as critical; CVE-2024-21762 demonstrates how unpatched vulnerabilities in remote access infrastructure can enable deep network compromise
- Incident response playbooks should account for anti-forensics tactics like log deletion; preserving evidence before cleanup is essential, and credential rotation must be prioritized over simple patching since copied passwords and installed agents persist even after vulnerability remediation
Disclaimer: The above content is generated by AI and is for reference only.