← Blog · · df00tech

Attacker Used MeshCentral to Maintain Root-Level Access Inside Thai ISP 3BB's Network

security-news breach

Threat intelligence firm Hunt.io reported that an attacker had established persistent, remote control over internal systems belonging to 3BB, one of Thailand's largest broadband providers, using MeshCentral — a legitimate, open-source remote management platform. According to Hunt.io, the intrusion was discovered when researchers found a server the attacker had left exposed on the internet, containing the attacker's own toolset and what was described as a list of subscriber-related data. Full details of the initial access vector and the scope of data exposure had not been disclosed at the time of reporting.

Why It Matters

This case is a reminder that legitimate remote management and monitoring (RMM) tools remain an attractive choice for intrusions precisely because they blend into normal administrative traffic and often evade signature-based defenses. A large ISP compromise is significant beyond the victim organization: broadband providers sit at a chokepoint for subscriber traffic and credentials, meaning a foothold here could have downstream implications for subscriber account security and, potentially, further network access. Organizations running MeshCentral or similar RMM tooling (e.g., AnyDesk, ScreenConnect, TeamViewer) for legitimate IT operations should treat this as a signal to review how those tools are deployed, authenticated, and monitored.

What Defenders Should Watch For

  • Unexpected or unauthorized MeshCentral agents/servers running on endpoints, especially instances not provisioned through approved IT channels.
  • Outbound connections to unfamiliar or newly registered MeshCentral server infrastructure.
  • New local administrator or service accounts created around the time an RMM agent was installed.
  • Internet-exposed management or staging servers — as in this case, the intrusion was discovered via an attacker-controlled server left open to the internet, underscoring the value of routine external attack-surface scanning.
  • Review of any legitimate RMM tooling in your own environment: confirm inventory, restrict installation rights, and monitor for use outside expected admin workflows.
  • For ISPs and telecom operators specifically, heightened scrutiny of subscriber-facing credential stores and authentication systems for anomalous access patterns.

This is a developing story and the details above reflect what has been publicly reported so far; attribution, full scope, and root cause have not been confirmed. For the original reporting, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.