Hunt.io found an attacker inside 3BB’s network in Thailand using MeshCentral as a hidden backdoor to keep remote control of internal systems. The intrusion targeted subscriber data, internal portals, and a FortiGate SSL-VPN gateway, with evidence also pointing to possible overlap with the Jasmine network. #3BB #MeshCentral #FortiGate #CVE-2024-21762 #Jasmine
Keypoints
- An attacker maintained access inside 3BB using MeshCentral.
- The exposed server revealed tools, targets, and active control of internal machines.
- The attacker used scripts to expand access, gather credentials, and probe internal systems.
- The main objective appeared to be 3BB subscriber data in RADIUS databases.
- The toolkit also targeted a FortiGate SSL-VPN gateway with CVE-2024-21762 exploit code.
Read More: https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html