Skip to content

Security1 publisher3 min readPublished

An attacker kept root inside Thai broadband provider 3BB with a hidden MeshCentral install

Hunt.io captured the operator's own server on June 3, 2026, while the intrusion was live. The files on it show password spraying across more than 55 internal hosts and a cleanup script written to erase everything except the MeshCentral agent.

The Watch · Security desk

Photograph accompanying An attacker kept root inside Thai broadband provider 3BB with a hidden MeshCentral install
Photo: thehackernews.com

What happened

  • Hunt.io captured a server the attacker had left open on the internet on June 3, 2026, while the operation was still live, and it held the attacker's tools plus a list of machines under their control.
  • Hunt.io said the goal was subscriber data, and scripts were built to copy out 3BB's RADIUS databases, though the evidence shows those stores were targeted and no data leaving them.
  • The kit's most developed component was a complete exploit for CVE-2024-21762 aimed at a 3BB FortiGate SSL-VPN gateway that was running affected firmware.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Detection here has to key on unexpected MeshCentral enrollments and unfamiliar control servers, because the component built to persist was a legitimate admin tool rather than malware with a signature.
  • decision Any shop running remote management software has to define what an authorized install looks like, since a hidden agent in a victim-named device group is indistinguishable from admin traffic until enrollments are compared against inventory.
  • cost Cleanup costs a full credential reissue across SSH keys, RADIUS and database passwords, VPN certificates and application secrets, on the assumption each was read while the operator held root.
  • exposure 3BB subscribers carry the exposure, because the credentials that authenticate their broadband sessions sit in the databases the scripts were written to copy.

MeshCentral is free, and it is what an IT team would install to manage computers remotely [4]. The recovered settings show the agents set to run hidden, checking in to a control server the attacker operated at www.ayuthayatech[.]com under a device group named TH-3BB [5]. Hunt.io said attackers increasingly abuse this kind of software because it is trusted and its activity blends in with routine administration [6].

Responders should read the cleanup script closely. It erased logs and deleted the attacker's other tools, and it left the MeshCentral agent in place on purpose so the access would survive [8]. Several machines on the recovered device list were connected and running with root privileges when the list was made, and the researchers said that showed the attacker held active administrative control at that point [7].

Inside the network the operator sprayed passwords over SSH against more than 55 internal computers and probed the internal sales portal at agent.3bb.co[.]th. Compromised machines were searched for stored passwords, database logins and SSH keys [9]. Other scripts could plant web shells and add SSH keys as backup ways back in [10]. The same server held a valid VPN certificate from 3BB's own systems and active login sessions for services on the Jasmine network. 3BB was once part of Jasmine and still shares infrastructure with it. Hunt.io said this suggested the attacker was working against both, and it stopped short of saying Jasmine itself had been breached [12].

How the attacker first got in is not established [13]. The most developed part of the kit targeted a 3BB FortiGate SSL-VPN gateway at mail.3bb.co[.]th, and it held a complete exploit for CVE-2024-21762. That 2024 Fortinet flaw lets an attacker run code on the device without logging in. The targeted gateway was running an affected firmware version [14]. Hunt.io recovered no sign that the exploit ran or that it was the way in [15]. A gateway still on vulnerable firmware when the server was captured in June 2026 is about two years of exposure on the box the attacker was aiming at [21].

Fortinet's advisory says that if you cannot patch at once you should turn off SSL-VPN, and that turning off web mode alone is not a valid workaround [18]. Patching does not remove an agent that is already installed or reset a password that has already been exposed [20]. Hunt.io's remediation list runs to SSH keys, database and RADIUS passwords, VPN certificates and application secrets, alongside a hunt for MeshCentral agents and management servers that are not in inventory [19][20].

The attacker has since closed the exposed directory. The evidence describes the intrusion as it stood in early June, so whether the access inside 3BB still holds is an open question [16]. Hunt.io said it notified the affected companies and the relevant national response team before publishing [17].

What to watch

  • Whether Jasmine confirms or rules out compromise of its own systems, given the live sessions found on the attacker's server.
  • Whether 3BB or Thailand's national response team publishes anything to subscribers about the RADIUS credential stores.
  • Whether the ayuthayatech control server, or a replacement, keeps taking agent check-ins now that the open directory is closed.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories