3BB Attacker Leveraged MeshCentral Backdoor for Root Access and Credential Theft
Threat actors exploited a MeshCentral backdoor to gain root access within the network of Thai broadband provider 3BB, targeting subscriber credentials.

Threat actors successfully infiltrated the network of 3BB, a major Thai broadband provider, and established persistent remote access using a backdoor within the legitimate MeshCentral remote management tool. The intrusion was uncovered by threat intelligence firm Hunt.io, which discovered an attacker-controlled server left exposed online containing the tools and data used in the operation.
The attackers utilized MeshCentral, a popular open-source remote management solution, to maintain a foothold within 3BB's internal network. This allowed them to operate with a high degree of stealth, blending in with legitimate administrative traffic. The firm's analysis revealed that the threat actors were actively targeting subscriber credentials, indicating a potential motive for data theft or identity fraud.
Hunt.io's discovery stemmed from monitoring an attacker-controlled server that had been inadvertently exposed to the internet. This server acted as a command-and-control (C2) hub, housing the tools the attackers employed and logs detailing their activities within the compromised network. The presence of this exposed server provided crucial insights into the methods and objectives of the intrusion.
While the specific entry vector into 3BB's network has not been detailed, the use of a MeshCentral backdoor suggests a potential compromise of an existing installation or the exploitation of a vulnerability within the tool itself. MeshCentral is widely used for remote IT support and management, making it an attractive target for attackers seeking to gain privileged access to corporate environments.
The implications of this breach are significant, given 3BB's large subscriber base in Thailand. The potential theft of subscriber credentials could lead to widespread identity theft, financial fraud, and further downstream attacks against affected customers. The attackers' ability to achieve root access underscores the severity of the compromise.
This incident highlights the dual-use nature of legitimate remote management tools. While essential for IT operations, their compromise can provide attackers with powerful capabilities for lateral movement and data exfiltration. Organizations relying on such tools must ensure they are securely configured, regularly updated, and monitored for suspicious activity.
Further investigation is likely underway to determine the full scope of the breach, identify the specific vulnerabilities exploited, and attribute the attack to a particular threat actor group. The incident serves as a stark reminder of the persistent threats facing critical infrastructure providers and the importance of robust cybersecurity defenses.