AI Weekly Malaysia

Back to items Summaries

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

ID
24366
Status
summarized
Published
15 Sep 2026, 2:01 AM
Fetched
15 Sep 2026, 4:45 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
15 Sep 2026, 4:48 AM
Tags
Audience
developersai_agent_users

What happened

Threat intelligence firm Hunt.io uncovered a live intrusion inside 3BB, one of Thailand's largest broadband providers, by capturing an exposed server the attacker had left internet-facing on June 3, 2026. The attacker used MeshCentral—a free remote-management tool—configured as a hidden backdoor reporting to a control server at www.ayuthayatech[.]com, and ran password-spraying scripts against 55+ internal machines, probed 3BB's sales portal, and built tools to exfiltrate RADIUS databases containing subscriber login credentials.

Why it matters

If you run remote management tools like MeshCentral, TeamViewer, or similar software in your infrastructure, this incident shows exactly how attackers repurpose them as stealthy backdoors that blend in with legitimate admin activity. Malaysian and SEA builders managing telco-adjacent or subscriber-facing systems should audit whether their remote management agents are configured in ways that could be covertly repurposed, and ensure RADIUS and credential stores are segmented from general network access.

Discussion angle

How attackers weaponize trusted IT admin tools like MeshCentral to maintain persistence—and what configuration patterns (device group naming, control server domains, agent visibility) would let you detect this in your own environment before a breach is found by accident.

Top