Thai Broadband Provider 3BB Targeted in Sophisticated Breach Using Legitimate Remote Management Software

A significant security breach targeting 3BB, one of Thailand’s most prominent broadband service providers, has exposed critical vulnerabilities in how telecommunications infrastructure is being exploited by modern threat actors. According to a detailed report published by threat intelligence firm Hunt.io, an unidentified attacker successfully established persistent, administrative-level access within the provider’s internal network. The intrusion, which was identified in June 2026, highlights a dangerous trend in cybersecurity: the weaponization of legitimate remote-management tools to camouflage malicious activity and evade traditional endpoint detection systems.
The investigation into the breach began when researchers at Hunt.io discovered an exposed server connected to the public internet. This server, which had been left unsecured by the threat actor, acted as a command-and-control repository, housing an extensive suite of exploitation tools, logs of compromised assets, and scripts designed to facilitate lateral movement across the 3BB network.
The Anatomy of the Intrusion
The attackers utilized a sophisticated methodology to maintain a foothold within the 3BB environment. Central to their operation was the deployment of MeshCentral, an open-source, legitimate remote-administration platform. While MeshCentral is a vital tool for IT administrators seeking to manage dispersed computer fleets, its ability to provide seamless, graphical remote access makes it an attractive target for threat actors.
By installing MeshCentral agents on internal machines, the intruders were able to maintain a persistent, "hidden" backdoor. These agents were configured to report back to a malicious control server hosted at www.ayuthayatech[.]com. The setup was highly organized, with internal machines categorized under a specific device group labeled "TH-3BB," suggesting a high level of operational maturity and a long-term strategy for data exfiltration or system sabotage.

A Chronology of the Attack
The timeline of the breach reveals a methodical approach to network penetration. While the initial vector of entry remains a subject of ongoing forensic analysis, evidence suggests the attackers possessed a high degree of familiarity with 3BB’s edge infrastructure.
- Early 2026: Preparatory phase, likely involving reconnaissance of 3BB’s public-facing assets, including their FortiGate SSL-VPN gateways.
- June 3, 2026: Hunt.io researchers identified the exposed server. At this time, the operation was active, with the attacker maintaining root-level access to multiple internal servers and workstations.
- Post-Discovery: Upon the realization that their infrastructure had been compromised by researchers, the attackers took swift action to purge their logs and deactivate the exposed management directory.
- Ongoing Investigation: While the public-facing footprint of the attack has been obscured, the lingering question remains whether the threat actor has successfully deployed secondary or tertiary persistence mechanisms that remain undetected.
Exploitation of Edge Infrastructure
A critical aspect of the Hunt.io report is the discovery of tools specifically designed to exploit Fortinet’s FortiGate SSL-VPN appliances. The attacker’s server contained a comprehensive exploit kit targeting CVE-2024-21762, a critical vulnerability in FortiOS that allows for unauthenticated remote code execution.
The presence of this exploit kit on the attacker’s server is significant. While researchers could not definitively confirm that this specific vulnerability was the "patient zero" vector for the breach, the fact that the targeted gateway was running a vulnerable version of the firmware strongly suggests it was the primary point of entry. This underscores a perennial issue in the telecommunications sector: the rapid pace of vulnerability discovery versus the slower cycle of patch management in enterprise-grade network hardware.
Lateral Movement and Data Objectives
Once inside the perimeter, the attackers did not simply sit idle. Recovered scripts indicate a calculated campaign to broaden their influence. The intruders executed "password spraying" attacks—a technique where a single, common password is tested against a large number of accounts—targeting over 55 internal computers via the Secure Shell (SSH) protocol.
The primary objective appeared to be the acquisition of sensitive subscriber data. The attacker’s toolkit included scripts specifically configured to interface with and extract information from RADIUS databases. These databases are the backbone of broadband authentication, storing the credentials that allow customers to connect to the internet. While there is no current evidence confirming that the exfiltration was successful, the intent to harvest these credentials indicates a high-level motivation, likely related to selling access to the provider’s network or performing large-scale identity theft.

Furthermore, the attackers probed the internal sales portal (agent.3bb.co[.]th) and searched for stored SSH keys and database logins. The inclusion of web shells—malicious scripts that allow attackers to issue commands to a web server—suggests the threat actor intended to establish long-term, non-volatile access to 3BB’s web-based services.
Cross-Network Implications
The discovery also highlighted a potential spillover effect. The compromised server contained valid VPN certificates and active session tokens related to the Jasmine network, a company that shares infrastructure and historical ties with 3BB. This indicates that the threat actor viewed the 3BB breach as a gateway to a broader ecosystem. While the researchers did not verify a full-scale compromise of Jasmine, the presence of these credentials suggests that the security of one entity in a shared-infrastructure environment is intrinsically linked to the other.
The Challenge of "Living off the Land"
The use of MeshCentral by the attackers is a textbook example of a "living off the land" (LotL) attack. In these scenarios, attackers avoid using custom, easily detectable malware in favor of tools that are already trusted by an organization’s security software. Because MeshCentral is frequently used by legitimate IT departments, traffic to its associated domains and the presence of its agents often fail to trigger the heuristic alarms of Endpoint Detection and Response (EDR) systems.
This breach serves as a stark reminder that administrative tools are double-edged swords. If an attacker gains sufficient privileges to install such software, they essentially become a "privileged user" in the eyes of the system. Defenders must now account for the authorized use of remote management software and implement strict monitoring for any unauthorized instances or unusual configurations of these tools.
Official Responses and Mitigation
Both Hunt.io and the affected entities have emphasized the necessity of a coordinated response. The researchers confirmed they notified the relevant Thai national cybersecurity response teams prior to the public disclosure of their findings.

For organizations operating similar infrastructure, the industry consensus for mitigation is clear:
- Patch Management: Immediate remediation of known vulnerabilities in edge devices, particularly SSL-VPN gateways, is non-negotiable.
- Strict Egress Filtering: Organizations must restrict the ability of internal servers to communicate with unknown or untrusted external control domains, which would have disrupted the MeshCentral agents’ communication.
- Credential Hygiene: The rotation of SSH keys and the implementation of multi-factor authentication (MFA) across all administrative interfaces are critical to preventing the type of lateral movement observed in this attack.
- Endpoint Auditing: Security teams must regularly audit for the presence of remote management tools, verifying that every instance is authorized and accounted for by the IT department.
Broader Cybersecurity Implications
The 3BB breach is not merely an isolated incident but a symptom of the increasing complexity of securing large-scale telecommunications providers. As these companies continue to digitize their operations and integrate disparate services, the "attack surface"—the total sum of vulnerabilities that can be exploited—expands exponentially.
The shift toward using legitimate management software for malicious purposes represents a maturation of threat actor tactics. It moves the battleground away from signature-based detection toward behavioral analysis. Security operations centers (SOCs) must evolve to identify anomalies in administrative behavior rather than just looking for known malicious file signatures.
As of the latest reports, the exposed server has been taken offline, and the specific directory used by the attackers is no longer accessible. However, the potential for persistent, dormant backdoors within the 3BB network remains a significant concern for stakeholders. The long-term impact on subscriber trust and the potential for secondary data breaches continue to be monitored by regional cybersecurity experts.
The incident serves as a definitive case study on the importance of proactive threat hunting. Had Hunt.io not discovered the exposed server, the attacker’s presence might have remained undetected for months or even years, potentially leading to a catastrophic data loss event. For the telecommunications industry, the lesson is clear: in the modern threat landscape, the most dangerous tools are often the ones that are already installed on your machines.







