The intrusion uncovered inside 3BB, one of Thailand’s largest broadband providers, is a strong example of how modern attackers increasingly prefer to abuse legitimate administrative tools rather than deploy obviously malicious software that security products are specifically designed to detect. Researchers found that the attacker had gained control of internal systems and was using MeshCentral, a legitimate remote-management platform normally used by IT teams, as a persistent backdoor into compromised machines. What makes this particularly concerning is that several systems enrolled in the attacker-controlled MeshCentral environment were reportedly operating with root privileges, giving the intruder the highest level of administrative control over those machines. Instead of relying solely on custom malware, the attacker effectively converted trusted remote-management software into long-term command-and-control infrastructure, allowing malicious activity to resemble ordinary system administration and therefore potentially remain unnoticed for much longer.

The way persistence was maintained is equally important because the attacker reportedly created a cleanup process designed to remove logs and other malicious tools while deliberately leaving the MeshCentral agent installed. That behaviour demonstrates a clear understanding of incident response and forensic investigation, because the attacker was not merely attempting to hide evidence but was selectively preserving the mechanism that would allow access to continue after other artifacts had been removed. This is an important lesson for defenders because deleting malware or patching the original vulnerability does not necessarily remove an attacker who has already established multiple persistence mechanisms. Once an environment has been compromised, security teams need to assume that the adversary may have created secondary access paths through remote-management software, SSH keys, web shells, privileged accounts, scheduled tasks or modified system components, which means eradication requires understanding the entire attack chain rather than simply addressing the first vulnerability that is discovered.

The attacker also appears to have actively expanded access inside the 3BB environment, using password-spraying scripts against more than 55 internal systems over SSH while probing internal applications and searching compromised machines for stored passwords, database credentials and SSH keys. This behaviour demonstrates how quickly an initial foothold can evolve into a broader identity and credential compromise, especially when administrative credentials or secrets are stored on servers in locations accessible to privileged users. Once attackers obtain even a small number of valid credentials, they can begin moving laterally between systems without generating the obvious indicators associated with exploitation, because their activity increasingly resembles legitimate authenticated access. This is why organisations need to monitor not only failed login attempts and vulnerability exploitation but also unusual successful authentication, unexpected use of privileged accounts, abnormal SSH activity and access patterns that do not match the normal behaviour of administrators or systems.

Perhaps the most significant aspect of the intrusion is the apparent targeting of 3BB’s subscriber authentication infrastructure. The recovered scripts were reportedly designed to copy the company’s RADIUS databases, which contain credentials used by broadband subscribers to authenticate to the network. Although the available evidence showed that these databases were targeted rather than confirming that they were successfully exfiltrated, the intent alone demonstrates the strategic value attackers place on telecommunications authentication systems. Compromise of subscriber credentials can create risks extending far beyond the ISP itself, potentially enabling unauthorized network access, subscriber impersonation or further attacks against services that trust those authentication systems. Telecommunications providers therefore need to treat identity stores such as RADIUS, AAA infrastructure, VPN credentials and subscriber databases as critical security assets that require additional segmentation, strong access controls, encryption, monitoring and strict limitations on which systems can interact with them.

The presence of a valid VPN certificate associated with 3BB and active sessions involving services on the Jasmine network adds another concerning dimension to the incident because it illustrates how compromised credentials and trusted certificates can potentially extend an attack beyond the originally breached organisation. Certificates, API keys, SSH keys and other machine credentials often receive less attention than human passwords, yet they can provide extremely powerful access because they are designed to authenticate systems automatically and may remain valid for long periods. Once attackers obtain such credentials, they may be able to establish trusted connections without triggering the authentication challenges typically associated with user accounts. Security teams therefore need a comprehensive inventory of machine identities and certificates, clear ownership and expiration policies and the ability to rapidly revoke and rotate them when compromise is suspected.

The investigation also uncovered a toolkit targeting a FortiGate SSL-VPN gateway that was reportedly running firmware affected by CVE-2024-21762, a serious vulnerability capable of allowing unauthenticated remote code execution. Importantly, researchers did not confirm that this vulnerability was actually used to gain initial access, and that distinction matters because technical evidence should never be stretched simply to produce a convenient narrative. What the presence of the exploit does demonstrate, however, is that the attacker had both the capability and intent to target internet-facing remote-access infrastructure. VPN gateways, firewalls and other edge security appliances remain exceptionally attractive targets because compromising a single device can potentially provide access to internal networks while bypassing many endpoint-focused security controls. Organisations therefore need to treat exposed security appliances as high-priority assets for vulnerability management and should not allow the term “security device” to create a false sense that the device itself requires less protection.

This incident also reinforces why vulnerability remediation cannot end with installing a patch. If an attacker has already exploited an edge device, patching prevents the same vulnerability from being used again but does nothing to remove persistence mechanisms, invalidate stolen credentials or undo configuration changes already made inside the environment. An organisation that patches a compromised VPN appliance but leaves attacker-installed remote-management agents, stolen SSH keys or valid certificates untouched may technically close the vulnerability while leaving the attacker fully operational. Effective response therefore requires patching to be combined with credential rotation, certificate revocation, threat hunting, integrity verification and detailed investigation of lateral movement, because the security objective is not merely to remove the vulnerability but to restore trust in the affected environment.

There is another important operational lesson in the fact that the intrusion was uncovered after researchers discovered an attacker-controlled server that had been left exposed to the internet. That server reportedly contained the attacker’s own tools, device information and evidence of compromised systems, providing researchers with an unusual window into the operation while it was still active. Organisations cannot depend on attackers making such mistakes, which means defenders need their own visibility capable of identifying similar activity internally through endpoint telemetry, network monitoring, DNS logs, privileged-access monitoring and behavioural analytics. Unexpected connections to unknown remote-management infrastructure, installation of new management agents or systems suddenly communicating with unfamiliar command servers should generate high-priority alerts, particularly when those systems hold administrative privileges.

The case also demonstrates why legitimate remote monitoring and management tools deserve much greater scrutiny inside enterprise and service-provider networks. Products such as MeshCentral, commercial RMM platforms and other administrative utilities are designed to provide exactly the capabilities attackers want, including remote command execution, file transfer, persistent connectivity and privileged control. Blocking every such tool is often impractical because IT teams legitimately depend on them, but organisations should maintain an approved inventory and treat any unrecognized remote-management software as potentially hostile until proven otherwise. Network controls should restrict which management servers endpoints are permitted to contact, while endpoint monitoring should detect unauthorized installation or execution of remote-access agents. The distinction between legitimate administration and malicious activity increasingly lies not in the software being used but in who installed it, where it connects and whether its behaviour is expected.

For internet service providers, the implications are particularly serious because compromise of internal systems can affect not only corporate infrastructure but also authentication platforms, subscriber information and interconnected networks. An ISP occupies a uniquely sensitive position in the digital ecosystem because large numbers of individuals and businesses rely on its infrastructure for connectivity, and attackers gaining privileged access to those systems may obtain opportunities unavailable in a conventional enterprise breach. This makes segmentation between corporate IT, subscriber management, network operations, billing platforms and authentication infrastructure especially important, while administrative access to those environments should be tightly controlled, logged and continuously reviewed.

The broader cybersecurity lesson from the 3BB intrusion is that trust in software must never become trust in behaviour. MeshCentral itself did not need to be malicious for the attacker to use it as a backdoor, just as valid SSH keys, legitimate VPN certificates and administrator accounts can all become attack tools once they fall under adversary control. Modern security therefore needs to move beyond simplistic distinctions between trusted and untrusted applications and instead continuously evaluate identity, privilege, destination, behaviour and context. A legitimate tool running with root privileges and communicating with an unknown external management server should be treated as suspicious regardless of whether the executable is digitally signed or commonly used by system administrators. In an environment where attackers increasingly live off trusted tools and stolen identities, understanding what a system is doing has become far more important than simply recognizing the name of the software performing the action.


An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of

Source: 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials via The Hacker News — published 14 Sep 2026.