3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

Summary

An attacker gained root access to the network of 3BB, a major Thai broadband provider, by exploiting a backdoor within the legitimate management tool MeshCentral. The attacker's goal was to steal subscriber credentials, as discovered by threat intelligence firm Hunt.io.

IFF Assessment

FOE

This article details a successful network intrusion and credential theft, representing a win for attackers and a setback for defenders.

Defender Context

This incident highlights the risk of legitimate remote management tools being abused as backdoors. Defenders should monitor for unusual activity on such tools and ensure they are properly secured and configured to prevent unauthorized access and lateral movement.

Read Full Story →