Threats · 12h ago
Hunt.io said it found an active intrusion inside Thailand’s 3BB on June 3, with an attacker holding root access, running MeshCentral as a hidden backdoor, and aiming scripts at subscriber RADIUS databases and internal credentials.
The attacker used MeshCentral, a legitimate remote-management tool, so the control channel looked like ordinary admin traffic instead of obvious malware. Hunt.io also recovered scripts that sprayed SSH passwords, searched for stored passwords and SSH keys, and were built to copy out the company’s RADIUS databases, which hold the login credentials broadband customers use to get online.
That puts the blast radius at the subscriber-authentication layer, not just on one infected host. If those RADIUS or internal admin credentials were reused, the compromise could outlive the original entry point and let an intruder impersonate customers across ISP services.
1 source covering this story
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Researchers found an attacker with root access inside 3BB using MeshCentral for persistence and targeting subscriber RADIUS databases.
Part of the PlainSec briefing for 2026-09-15