3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Thai broadband provider 3BB was infiltrated by an attacker who maintained persistent root access using a hidden MeshCentral backdoor, according to findings published by Hunt.io. The intrusion involved the use of a full exploit toolkit for the Fortinet FortiGate SSL-VPN gateway, specifically targeting CVE-2024-21762 on the mail.3bb.co.th host, although researchers noted it remains unconfirmed whether this specific vulnerability was used for initial entry. While evidence shows the attackers targeted 3BB’s RADIUS databases for subscriber credentials and probed related infrastructure belonging to Jasmine, there is no confirmation that customer data was exfiltrated. Organizations are advised to audit for unauthorized MeshCentral agents, rotate exposed credentials, and ensure FortiGate devices are patched against CVE-2024-21762.