Attacker Used Legitimate Remote-Access Tool to Maintain Hidden Control Inside Major Thai ISP
Security firm Hunt.io discovered an active intrusion inside the network of 3BB, one of Thailand's largest broadband providers, after finding a server the attacker had accidentally left exposed on the internet. That server contained the attacker's own tools and a list of internal machines already under their control, including evidence of full administrative (root) access to at least one internal server.
To keep that access, the attacker installed MeshCentral, a free and legitimate remote-management tool that IT teams commonly use, but configured it as a hidden backdoor reporting to a server the attacker controlled. A cleanup script was designed to erase other traces of the intrusion while deliberately leaving the MeshCentral agent running, so access would survive even after other tools were removed. This is part of a wider trend where attackers abuse trusted administration software because its activity blends in with normal IT operations and is less likely to raise alarms.
Once inside, the attacker attempted to expand their foothold by spraying passwords against more than 55 internal computers, probing an internal sales portal, and searching for stored credentials and SSH keys. Scripts were also built to copy out 3BB's RADIUS databases, which store the login credentials broadband subscribers use to get online. Hunt.io noted the evidence shows these databases were targeted, not confirmed as stolen.