3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
- ID
- 24366
- Status
- summarized
- Published
- 15 Sep 2026, 2:01 AM
- Fetched
- 15 Sep 2026, 4:45 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 15 Sep 2026, 4:48 AM
- Tags
- Audience
- developersai_agent_users
What happened
Threat intelligence firm Hunt.io uncovered a live intrusion inside 3BB, one of Thailand's largest broadband providers, by capturing an exposed server the attacker had left internet-facing on June 3, 2026. The attacker used MeshCentral—a free remote-management tool—configured as a hidden backdoor reporting to a control server at www.ayuthayatech[.]com, and ran password-spraying scripts against 55+ internal machines, probed 3BB's sales portal, and built tools to exfiltrate RADIUS databases containing subscriber login credentials.
Why it matters
If you run remote management tools like MeshCentral, TeamViewer, or similar software in your infrastructure, this incident shows exactly how attackers repurpose them as stealthy backdoors that blend in with legitimate admin activity. Malaysian and SEA builders managing telco-adjacent or subscriber-facing systems should audit whether their remote management agents are configured in ways that could be covertly repurposed, and ensure RADIUS and credential stores are segmented from general network access.
Discussion angle
How attackers weaponize trusted IT admin tools like MeshCentral to maintain persistence—and what configuration patterns (device group naming, control server domains, agent visibility) would let you detect this in your own environment before a breach is found by accident.