3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Executive Summary
A threat actor infiltrated 3BB's network and used the legitimate remote‑management tool MeshCentral as a backdoor to gain root access on internal machines. The attacker left an exposed server that contained its own tools and a list of subscriber credentials. Hunt.io uncovered the intrusion by analyzing the exposed server.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-14T18:01:49+00:00 - Category: threat-intel
Original Description: An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
"One who asks a question is a fool for five minutes; one who does not ask a question remains a fool forever."
— Unknown