BitNewsBot - 9/14/2026 8:34:57 PM - GMT (+0 )
- An attacker infiltrated 3BB, a major Thai broadband provider, using the legitimate remote management tool MeshCentral as a hidden backdoor.
- The attacker targeted 3BB‘s RADIUS databases containing broadband subscriber credentials, though data exfiltration was not confirmed.
- A recovered toolkit included an exploit for the Fortinet flaw CVE-2024-21762, aimed at the company’s SSL-VPN gateway, but proof of successful exploitation is missing.
- Researchers found evidence the attacker also had access to the Jasmine network, a former parent company, via a valid VPN certificate and active login sessions.
A sophisticated attacker infiltrated the network of 3BB, one of Thailand’s largest broadband providers, maintaining remote access through a legitimate management tool called MeshCentral, according to threat intelligence firm Hunt.io. Researchers discovered the intrusion on June 3, 2026, after spotting an exposed server holding the attacker’s tools and a list of compromised machines.
- Advertisement -
The attacker operated from inside 3BB‘s network and used MeshCentral to maintain root-level administrative control over internal servers. Attackers increasingly abuse such remote-management software because its activity blends with routine administration. A cleanup script on the server was designed to erase other tools while deliberately preserving the MeshCentral agent, ensuring persistent access.
The attacker’s primary goal appeared to be 3BB‘s subscriber data. Recovered scripts targeted the company’s RADIUS databases, which store broadband login credentials, though Hunt.io found no evidence data was actually taken. Inside the network, the attacker also probed the internal sales portal, sprayed passwords against over 55 internal machines, and searched for stored credentials and SSH keys.
The compromised server held an exploit for CVE-2024-21762, a serious Fortinet flaw from 2024 that allows code execution without authentication. The tooling was aimed at 3BB‘s FortiGate SSL-VPN gateway, but nothing recovered confirmed the exploit was successful. The same server also contained a valid VPN certificate from 3BB and active login sessions for services on the Jasmine network, suggesting the attacker worked against both companies, though a breach of Jasmine itself was not confirmed.
Hunt.io notified the affected companies and the relevant national response team before publishing its findings. Key indicators include the attacker’s IP address (92.63.180[.]133), the domain www.ayuthayatech[.]com acting as the MeshCentral control server, and specific persistence paths within 3BB‘s systems. The full technical details are available in Hunt.io’s report.
- Advertisement -
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:🔥 Join 1.2K Smart Traders
Get exclusive crypto insights, breaking news, and market analysis delivered straight to your inbox. No fluff, just facts.
You have successfully joined our subscriber list.
Binance
AdAltseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
Start Trading
read more


