Threat Intelligence

Attacker Used Legitimate Remote-Access Tool to Maintain Hidden Control Inside Major Thai ISP

The Hacker News · 15 Sept 2026
Key Takeaway Regularly audit which remote-management tools are installed on your network and who is using them, since attackers increasingly hide inside legitimate IT software rather than obvious malware.

Security firm Hunt.io discovered an active intrusion inside the network of 3BB, one of Thailand's largest broadband providers, after finding a server the attacker had accidentally left exposed on the internet. That server contained the attacker's own tools and a list of internal machines already under their control, including evidence of full administrative (root) access to at least one internal server.

To keep that access, the attacker installed MeshCentral, a free and legitimate remote-management tool that IT teams commonly use, but configured it as a hidden backdoor reporting to a server the attacker controlled. A cleanup script was designed to erase other traces of the intrusion while deliberately leaving the MeshCentral agent running, so access would survive even after other tools were removed. This is part of a wider trend where attackers abuse trusted administration software because its activity blends in with normal IT operations and is less likely to raise alarms.

Once inside, the attacker attempted to expand their foothold by spraying passwords against more than 55 internal computers, probing an internal sales portal, and searching for stored credentials and SSH keys. Scripts were also built to copy out 3BB's RADIUS databases, which store the login credentials broadband subscribers use to get online. Hunt.io noted the evidence shows these databases were targeted, not confirmed as stolen.

data breach remote access tool abuse credential theft ISP security MeshCentral

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.