Thai ISP 3BB Hit by MeshCentral Backdoor Targeting Subscriber Credentials
Threat intelligence firm Hunt.io has uncovered a sophisticated intrusion inside the network of 3BB, one of Thailand's largest broadband providers, where an attacker maintained persistent root-level access using MeshCentral, a legitimate remote management tool repurposed as a hidden backdoor. Researchers captured an exposed server on June 3, 2026, while the operation was still live, revealing the attacker's toolkit, a list of compromised machines, and configuration files showing the MeshCentral agents reporting to a control server hosted at www.ayuthayatech[.]com under a device group named "TH-3BB." The use of trusted administration software made the malicious activity blend in with routine IT operations, a tactic increasingly favored by advanced persistent threat actors.
Inside the network, the attacker worked to expand their foothold. Recovered scripts sprayed passwords against more than 55 internal hosts over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and harvested stored credentials, database logins, and SSH keys from compromised machines. Additional scripts were capable of planting web shells and adding unauthorized SSH keys for redundant access. A cleanup script was also deployed to erase logs and remove the attacker's secondary tools while deliberately preserving the MeshCentral agent, ensuring survival across remediation efforts. Security teams defending similar environments can audit exposed admin ports using a port scanner to identify unauthorized remote management endpoints.
The attacker's primary objective was 3BB's subscriber data. Multiple scripts were designed to exfiltrate the company's RADIUS databases, which store the authentication credentials broadband customers use to connect, though Hunt.io confirmed the evidence shows targeting rather than confirmed data exfiltration. The same server also held a valid VPN certificate from 3BB's infrastructure and active login sessions for services on the Jasmine network, a former 3BB subsidiary that still shares infrastructure, suggesting the attacker was operating against both organizations. The server also contained a full toolkit aimed at 3BB's FortiGate SSL-VPN gateway at mail.3bb.co[.]th, though how initial access was achieved remains undetermined. Indicators tied to the operation can be investigated further with a WHOIS lookup on the attacker's control domain, while subscribers concerned about credential exposure can verify their accounts with an email breach checker.