Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exposing the Shadowy Hands of Cybercrime: The Rise of MeshCentral and the 3BB Breach




A recent exposé by threat intelligence firm Hunt.io has shed light on a particularly insidious cyber attack on the network of 3BB, one of Thailand's largest broadband providers. The attackers, who were operating inside the network, maintained remote control of internal machines using a legitimate management tool called MeshCentral. This malicious tool was used to gain full administrative control, or root access, of an internal server, and was subsequently used to carry out a range of nefarious activities. The attack highlights the growing threat of remote-management software abuse and the need for IT teams to be aware of the risks associated with this type of tool. Organizations should take proactive steps to protect themselves against similar threats, including patching, rotating credentials, and preserving logs and evidence. By doing so, they can reduce their exposure to similar threats and protect themselves against the growing threat of remote-management software abuse.

  • 3BB, a Thai broadband provider, was targeted by a sophisticated cyber attack using MeshCentral, a legitimate remote management tool.
  • The attackers gained full administrative control of an internal server and carried out malicious activities, including password spraying and probing internal systems.
  • The attack highlights the increasing abuse of remote-management software by attackers, who use its trustworthiness to their advantage.
  • Organizations are advised to patch against known vulnerabilities, check for suspicious connections, rotate credentials, and preserve logs to reduce exposure to similar threats.



  • A recent exposé by threat intelligence firm Hunt.io has shed light on a particularly insidious cyber attack on the network of 3BB, one of Thailand's largest broadband providers. The attackers, who were operating inside the network, maintained remote control of internal machines using a legitimate management tool called MeshCentral. This malicious tool was used to gain full administrative control, or root access, of an internal server, and was subsequently used to carry out a range of nefarious activities.

    The researchers at Hunt.io discovered the intrusion by examining a server that the attackers had left open on the internet, which held the attackers' own tools and a list of machines already under their control. The tools on the server had been run from a computer inside 3BB's own network, and one recovered file showed that the attackers had gained root access. To maintain their access, the attackers had installed MeshCentral, a free tool that IT teams typically use to manage computers remotely. However, the attackers had configured it as a hidden backdoor, with the agents reporting to a control server that the attackers ran at www.ayuthayatech[.]com, under a device group named TH-3BB.

    This breach highlights the increasing abuse of remote-management software by attackers, who take advantage of its trustworthiness and the fact that its activity blends in with routine administration. The attackers had also set up a device list, which named several machines that were connected and running with root privileges at the time the list was made. This showed that the attackers had active administrative control at that point. A separate cleanup script had been written to erase logs and delete the attackers' other tools while deliberately leaving the MeshCentral agent in place so that the access would survive.

    The attackers had also carried out a range of other malicious activities, including spraying passwords against more than 55 internal computers over SSH, probing 3BB's internal sales portal at agent.3bb.co[.]th, and searching compromised machines for stored passwords, database logins, and SSH keys. Other scripts could plant web shells, hidden pages that run an attacker's commands, and add SSH keys as backup ways back in. The attackers' main goal was 3BB's subscriber data, and scripts on the server were built to copy out the company's RADIUS databases, the systems that store the login credentials broadband customers use to get online.

    The server also pointed to a second target, a valid VPN certificate from 3BB's own systems and active login sessions for services on the Jasmine network, a company 3BB was once part of and still shares infrastructure with. Hunt.io said this suggested the attacker was working against both, though it did not confirm that Jasmine itself had been breached. The attack on 3BB is a stark reminder of the importance of securing remote-management software and the need for vigilance in the face of ever-evolving threats.

    The attack on 3BB was carried out using a tool called MeshCentral, which is a free tool that IT teams typically use to manage computers remotely. However, the attackers had configured it as a hidden backdoor, with the agents reporting to a control server that the attackers ran at www.ayuthayatech[.]com, under a device group named TH-3BB. This configuration allowed the attackers to maintain remote control of internal machines and gain full administrative control, or root access, of an internal server.

    The attackers had also set up a device list, which named several machines that were connected and running with root privileges at the time the list was made. This showed that the attackers had active administrative control at that point. A separate cleanup script had been written to erase logs and delete the attackers' other tools while deliberately leaving the MeshCentral agent in place so that the access would survive.

    The attackers had also carried out a range of other malicious activities, including spraying passwords against more than 55 internal computers over SSH, probing 3BB's internal sales portal at agent.3bb.co[.]th, and searching compromised machines for stored passwords, database logins, and SSH keys. Other scripts could plant web shells, hidden pages that run an attacker's commands, and add SSH keys as backup ways back in. The attackers' main goal was 3BB's subscriber data, and scripts on the server were built to copy out the company's RADIUS databases, the systems that store the login credentials broadband customers use to get online.

    The server also pointed to a second target, a valid VPN certificate from 3BB's own systems and active login sessions for services on the Jasmine network, a company 3BB was once part of and still shares infrastructure with. Hunt.io said this suggested the attacker was working against both, though it did not confirm that Jasmine itself had been breached.

    The attack on 3BB is a stark reminder of the importance of securing remote-management software and the need for vigilance in the face of ever-evolving threats. The use of MeshCentral as a hidden backdoor highlights the growing threat of remote-management software abuse, and the need for IT teams to be aware of the risks associated with this type of tool.

    The attack on 3BB also highlights the importance of regular security audits and the need for organizations to take proactive steps to protect themselves against cyber threats. The attackers had set up a device list, which named several machines that were connected and running with root privileges at the time the list was made. This showed that the attackers had active administrative control at that point. A separate cleanup script had been written to erase logs and delete the attackers' other tools while deliberately leaving the MeshCentral agent in place so that the access would survive.

    In light of this attack, organizations should take the following steps to protect themselves against similar threats:

    * Patch or confirm that FortiGate SSL-VPN appliances are fixed against CVE-2024-21762.
    * Check for MeshCentral agents you did not install, and for connections to management servers you do not recognize.
    * Rotate credentials that may have been exposed, including SSH keys, database and RADIUS passwords, VPN certificates, and application secrets.
    * Hunt for hidden ways back in, such as unexpected SUID files, web shells, changed SSH keys, and newly added remote-management software.
    * Preserve logs and evidence before cleaning up, because the attacker's own script was built to erase them.

    By taking these steps, organizations can reduce their exposure to similar threats and protect themselves against the growing threat of remote-management software abuse.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exposing-the-Shadowy-Hands-of-Cybercrime-The-Rise-of-MeshCentral-and-the-3BB-Breach-ehn.shtml

  • https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html


  • Published: Mon Sep 14 14:44:03 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us