3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

A recent high-profile cyber attack on Thailand’s third-largest telecommunications provider, 3BB, has left thousands of subscribers’ sensitive information exposed and vulnerable to exploitation. The attacker, who gained root access to the company’s network using a backdoor in the MeshCentral remote monitoring software, targeted subscriber credentials and other personal data.

The breach is particularly concerning due to the nature of the exploited vulnerability. MeshCentral allows administrators to remotely monitor and manage devices on their network, but it also creates a potential entry point for attackers if not properly secured. In this case, the attacker used the backdoor to gain elevated privileges, essentially becoming an administrator with full access to the system.

The attack is believed to have occurred through a combination of social engineering and exploitation of poor password practices. An individual claimed to be from 3BB’s IT department contacted an employee, convincing them to grant remote access using MeshCentral. Once inside, the attacker exploited weak passwords on various servers, ultimately gaining root access. This allowed them to extract sensitive data, including subscriber credentials, which can be used for identity theft or sold on the dark web.

The attack highlights the risks associated with the growing trend of IoT and device management tools being used in enterprise environments. While these solutions are designed to improve efficiency and reduce costs, they also introduce new vulnerabilities if not properly secured. In this case, 3BB’s reliance on a potentially insecure tool created an attractive target for attackers.

The aftermath of the breach has left many wondering what could have been done differently. Experts point out that even in cases where companies are vigilant about security, human factors like employee phishing and password weaknesses can still lead to catastrophic consequences. The incident serves as a reminder of the importance of robust password policies, regular software updates, and staff training on cybersecurity best practices.

For readers who manage or work with IoT devices, this breach should serve as a warning: ensure that your device management tools are properly secured, and that employees are aware of the risks associated with granting remote access. While it may seem like an innocuous step to grant someone administrative rights for maintenance purposes, it can have devastating consequences if not done correctly. By prioritizing security and taking proactive measures to mitigate risk, we can all do our part in preventing similar breaches from occurring in the future.


Source: The Hacker News — 2026-09-14