highAPT

3BB MeshCentral Backdoor Intrusion

First seen Sep 15, 2026 · Updated Sep 15, 2026

MeshCentralliving-off-the-landISPcredential-theftremote-access-toolThailandlegitimate-tool-abuse

An unidentified attacker maintained persistent, root-level remote access inside the network of 3BB, a major Thai broadband provider, by abusing the legitimate remote management tool MeshCentral. The intrusion was discovered after researchers at Hunt.io found an exposed attacker-controlled server containing their toolset and a list of harvested subscriber credentials. The incident highlights ongoing risk to telecom infrastructure from living-off-the-land techniques that evade traditional malware detection.

Technical Analysis

The attacker deployed MeshCentral, an open-source remote monitoring and management (RMM) platform, as a covert backdoor to obtain and maintain root-level access to internal 3BB systems, likely leveraging its legitimate agent-based architecture to blend in with normal administrative traffic and evade endpoint detection. Discovery occurred opportunistically when researchers identified an internet-exposed staging server used by the attacker, which contained offensive tooling and exfiltrated subscriber credential data, suggesting the operation targeted downstream customer accounts as well as internal infrastructure. The use of a legitimate, dual-use RMM tool rather than custom malware indicates a living-off-the-land approach designed to reduce detection by signature-based defenses and complicate attribution. No CVE or specific encryption/exploitation mechanism was disclosed in available reporting, and the intrusion vector into 3BB's network remains unconfirmed. For organizations running AI agents or automated pipelines that rely on ISP-provided connectivity or third-party RMM integrations, this incident underscores agent-relevant risk: compromised broadband infrastructure or credential theft at the ISP level can expose API keys, session tokens, or network paths used by agentic systems, and any environment running MeshCentral or similar RMM agents should treat unexpected root-level access as a potential precursor to broader credential and secrets exposure.

Affected Systems

3BB (Thailand broadband ISP) internal network infrastructure; systems running MeshCentral RMM agent; subscriber account/credential management systems

Indicators of Compromise

  • MeshCentral RMM agent (abused as backdoor)
  • Exposed attacker-controlled staging/server (specific IP/domain not disclosed in source)
  • Harvested subscriber credential lists (details not disclosed)

Remediation Steps

  1. 1

    Audit RMM tool deployments

    Inventory all instances of MeshCentral and other remote management tools across the environment; verify legitimacy of each deployment and remove unauthorized installations.

  2. 2

    Review privileged access logs

    Audit root/administrative access logs for anomalous authentication patterns, unusual session times, or unrecognized management sessions tied to RMM platforms.

  3. 3

    Force credential rotation

    Reset subscriber and internal administrative credentials that may have been exposed, and enforce MFA on all account access points.

  4. 4

    Network segmentation and monitoring

    Segment management/administrative networks from customer-facing systems and deploy monitoring for outbound connections to MeshCentral relay servers not under organizational control.

  5. 5

    Threat hunting for LOTL techniques

    Conduct proactive threat hunts focused on living-off-the-land tool abuse, correlating RMM agent installs with unexpected process trees or unauthorized configuration changes.

Industries Most Exposed

TelecommunicationsInternet Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.