CYBER DELTA FORCESearch

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.

CDF News DeskThe Hacker News14 Sept 2026, 11:31 pm
Image courtesy of The Hacker News. Original report
CDF REPORT

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the PointThe Hacker News · 15 Sept 2026, 4:56 pmHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackSecurityWeek · 15 Sept 2026, 2:39 pmInternational Meteor Organization Hit by Cyberattack, Weeks of Disruption ExpectedThe Cyber Express · 15 Sept 2026, 12:35 pmUK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox FindsThe Cyber Express · 15 Sept 2026, 11:39 am