3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Summary
An attacker gained root access to the network of 3BB, a major Thai broadband provider, by exploiting a backdoor within the legitimate management tool MeshCentral. The attacker's goal was to steal subscriber credentials, as discovered by threat intelligence firm Hunt.io.
IFF Assessment
FOE
This article details a successful network intrusion and credential theft, representing a win for attackers and a setback for defenders.
Defender Context
This incident highlights the risk of legitimate remote management tools being abused as backdoors. Defenders should monitor for unusual activity on such tools and ensure they are properly secured and configured to prevent unauthorized access and lateral movement.