ZeroHour
The Hacker Newspublished ()ingested [email protected] (The Hacker News)1
Part of a story covered by 3 sources: “Exposed Attacker Server Reveals FortiGate SSL-VPN Breach and MeshCentral Root Backdoor at Thai ISP 3BB” — merged summary and timeline →

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

highData breach exploited in the wildimportance 70CVE-2024-21762
AI summary · glm-5.3

Hunt.io found an attacker holding root access inside Thai ISP 3BB via a MeshCentral backdoor, targeting subscriber RADIUS credential databases.

Hunt.io discovered an exposed attacker server on June 3, 2026 revealing an ongoing intrusion at 3BB, one of Thailand's largest broadband providers. The attacker maintained hidden MeshCentral agents reporting to www.ayuthayatech[.]com (device group TH-3BB) and held root on internal servers. Recovered scripts sprayed passwords over SSH against more than 55 internal machines, planted web shells, added SSH keys, searched for stored credentials, and targeted RADIUS subscriber credential databases, though exfiltration was not confirmed. The toolkit included a full exploit for FortiGate SSL-VPN flaw CVE-2024-21762 against mail.3bb.co[.]th, but the initial access vector is unestablished, and a cleanup script erased logs while preserving the backdoor.

  • MeshCentral remote-management tool configured as hidden backdoor maintained root access on 3BB servers.
  • Password spraying hit over 55 internal machines via SSH; web shells and SSH keys added for persistence.
  • RADIUS databases holding subscriber credentials were targeted, but exfiltration is unconfirmed.
  • FortiGate toolkit included a CVE-2024-21762 exploit, though the entry vector remains unproven.
  • Log-wiping cleanup script deliberately preserved the MeshCentral agent to survive remediation.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21762
Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy

CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted.

Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority.

9.884% KEV ransomware
  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7
mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans)

Indicators of compromiseAll →

TypeIndicatorContext
domainagent.3bb.coeshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w
domainayuthayatech.comreporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing
domainco.ths over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,
domainhunt.iotacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc
Full article848 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalSep 14, 2026Network Security / Cyber Attack

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.

The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of machines already under their control.

The researchers captured the exposed server on June 3, 2026, while the operation was still live. The tools on it had been run from a computer inside 3BB's own network, and one recovered file showed the attacker gaining full administrative control, known as root, of an internal server.

To maintain that access, the attacker installed MeshCentral, a free tool that IT teams typically use to manage computers remotely. The recovered settings show it was configured as a hidden backdoor, with the agents reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB.

Attackers increasingly abuse this kind of remote-management software because it is trusted and its activity blends in with routine administration.

A device list recovered from the server named the machines enrolled in the attacker's MeshCentral setup. Several were connected and running with root privileges when the list was made, which the researchers said showed the attacker held active administrative control at that point.

A separate cleanup script was written to erase logs and delete the attacker's other tools while deliberately leaving the MeshCentral agent in place so that the access would survive.

Inside the network, the attacker worked to widen their access. Recovered scripts sprayed passwords against more than 55 internal computers over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords, database logins, and SSH keys. Other scripts could plant web shells, hidden pages that run an attacker's commands, and add SSH keys as backup ways back in.

Hunt.io said the attacker's main goal was 3BB's subscriber data. Scripts on the server were built to copy out the company's RADIUS databases, the systems that store the login credentials broadband customers use to get online. The evidence shows those databases were targeted, not that any data was taken.

The same server pointed to a second target. It held a valid VPN certificate from 3BB's own systems and active login sessions for services on the Jasmine network, a company 3BB was once part of and still shares infrastructure with. Hunt.io said this suggested the attacker was working against both, though it did not confirm that Jasmine itself had been breached.

How the attacker initially gained access to 3BB is not established. The server held a full toolkit aimed at a 3BB FortiGate SSL-VPN gateway, the remote-access box at mail.3bb.co[.]th, including a complete exploit for CVE-2024-21762, a serious 2024 Fortinet flaw that lets an attacker run code on the device without logging in. The targeted gateway was running a firmware version affected by the flaw.

But nothing Hunt.io recovered shows the exploit actually worked, or that it was how the attacker got in. The FortiGate tooling was the most developed part of the kit, yet it points to the attacker's capability and intent, not a confirmed break-in through that device.

The attacker has since closed the exposed directory. Whether they still have access inside 3BB is not known, because the evidence describes the intrusion as it stood in early June, not today.

The researchers said they notified the affected companies and the relevant national response team about their findings before publishing.

What Defenders Should Do

The recovered toolkit points to a clear set of steps for organizations running similar edge devices and authentication systems:

  • Patch or confirm that FortiGate SSL-VPN appliances are fixed against CVE-2024-21762. Fortinet's advisory says that if you cannot patch at once, you should turn off SSL-VPN, and that turning off web mode alone is not a valid workaround.
  • Check for MeshCentral agents you did not install, and for connections to management servers you do not recognize.
  • Rotate credentials that may have been exposed, including SSH keys, database and RADIUS passwords, VPN certificates, and application secrets. Patching does not remove an agent that is already installed or reset a password that has already been copied.
  • Hunt for hidden ways back in, such as unexpected SUID files, web shells, changed SSH keys, and newly added remote-management software.
  • Preserve logs and evidence before cleaning up, because the attacker's own script was built to erase them.

Key indicators from the report, shown in defanged form:

  • IP address: 92.63.180[.]133, the attacker's server (port 8888 held the open directory, port 9443 received the exploit callback)
  • Domain: www.ayuthayatech[.]com, the MeshCentral control server
  • MeshCentral group: TH-3BB
  • Persistence paths: /usr/local/bin/.rc, a hidden backdoor, and /usr/local/mesh_services/meshagent/
  • Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal)

The full list of indicators, along with the technical details, is in Hunt.io's report.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html