3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
AI Summary
An attacker gained and maintained persistent access within the network of 3BB, a major Thai broadband provider, by deploying a hidden MeshCentral backdoor configured to report to a malicious command-and-control server. The attacker used legitimate administrative tools and scripts to escalate privileges, conduct internal reconnaissance, and target RADIUS databases containing subscriber credentials. Indicators show active administrative control over internal systems, password spraying, and attempts to exfiltrate sensitive authentication data. The intrusion was discovered via an exposed external server containing attacker tools, though the initial access vector remains unconfirmed despite evidence of exploit capabilities for CVE-2024-21762 in FortiGate devices.
AI-extracted · verify before operational use