3BB Network Compromised via MeshCentral Backdoor for Subscriber Credential Theft
A threat actor infiltrated 3BB's network using a MeshCentral backdoor to achieve root access and target subscriber credentials, exploiting unpatched vulnerabilities and deploying persistence mechanisms. The attack involved password spraying, web shell deployment, and targeting RADIUS databases, with indicators pointing to potential ongoing threats.
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.
The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
*** END OF TRANSMISSION ***