Thai Broadband Provider 3BB Targeted in Sophisticated Cyber Espionage Campaign Utilizing Legitimate Management Tools

In a sophisticated cyber intrusion that highlights the growing trend of "living-off-the-land" attacks, researchers at the threat intelligence firm Hunt.io have uncovered a covert operation targeting 3BB, one of Thailand’s most prominent broadband service providers. The attackers, whose origins remain under investigation, successfully infiltrated the company’s internal network and maintained persistent, high-level administrative access by repurposing legitimate remote management software. This breach, which was identified while the operation was still active in early June 2026, underscores the significant risks posed when threat actors exploit the very tools designed to secure and manage corporate infrastructure.
The discovery was made by accident after researchers identified an improperly secured server left exposed on the public internet. This server acted as an operational command hub for the attackers, housing a cache of malicious tools, internal logs, and a comprehensive list of compromised machines within the 3BB environment. The exposure provided a rare window into the tactics, techniques, and procedures (TTPs) of an adversary that prioritized stealth, persistence, and the exfiltration of sensitive subscriber data.
Chronology of the Intrusion
The timeline of the breach suggests a calculated and methodical approach to network infiltration. While the exact date of the initial entry remains unconfirmed, the presence of advanced tooling within the attacker’s command-and-control server points to a sophisticated operation.
On June 3, 2026, Hunt.io researchers captured the exposed server, discovering that the intruders were actively managing machines inside 3BB’s network. Forensic analysis of the server’s contents revealed that the attackers had successfully achieved "root" level access—the highest level of privilege—on multiple internal servers.

Following their initial access, the attackers implemented a strategy of persistence by deploying MeshCentral, an open-source, legitimate remote management and monitoring (RMM) platform. By configuring MeshCentral agents to operate as hidden backdoors reporting to an external domain (ayuthayatech[.]com) under a specific device group labeled "TH-3BB," the attackers ensured they could maintain control even if traditional administrative credentials were changed.
By mid-June, the threat actors were observed executing cleanup scripts designed to erase system logs and remove secondary forensic footprints. Crucially, they left the MeshCentral agents intact, effectively masking their presence within the routine administrative traffic of the broadband provider.
Tactical Methodology: The Abuse of Trusted Software
The use of MeshCentral represents a strategic shift in modern cyber warfare. Rather than relying on custom-built, signature-heavy malware that is easily detected by endpoint protection software, threat actors are increasingly favoring "dual-use" tools. Because MeshCentral is frequently used by legitimate IT departments to perform remote troubleshooting and system management, its activity often blends seamlessly into the baseline network noise of a large telecommunications firm.
The attackers’ internal operations were equally methodical. Recovered scripts from the command server indicated a multi-stage approach to network reconnaissance and lateral movement:
- Credential Harvesting: The attackers utilized password-spraying techniques against at least 55 internal computers via Secure Shell (SSH) protocols. They specifically targeted stored passwords, database credentials, and SSH keys to escalate their privileges further.
- Infrastructure Probing: The threat actors systematically probed the 3BB internal sales portal (agent.3bb.co[.]th), searching for vulnerabilities that could allow for unauthorized data access or the injection of web shells.
- Persistence Mechanisms: Beyond MeshCentral, the attackers prepared backups by planting web shells—hidden scripts that allow for remote command execution through a web server—and by inserting rogue SSH keys into the authorized_keys files of compromised machines.
Targeted Assets and Strategic Intent
The primary objective of this campaign appears to have been the exfiltration of subscriber data, with a specific focus on RADIUS (Remote Authentication Dial-In User Service) databases. These databases are the backbone of broadband operations, storing the login credentials, service profiles, and usage history of the company’s massive customer base. While the evidence recovered by Hunt.io indicates that the attackers were actively preparing to siphon this data, there is no definitive proof at this stage that a large-scale exfiltration event was completed.

Furthermore, the reach of the intrusion extended beyond 3BB. The recovered server contained active login sessions and a valid VPN certificate associated with the Jasmine network. Given the historical and operational ties between 3BB and Jasmine, this discovery suggests that the attackers may have been orchestrating a supply-chain-style attack, aiming to leverage access from one network to pivot into a secondary, interconnected environment.
The Fortinet Connection
One of the most concerning aspects of the investigation involves a specialized toolkit found on the attacker’s server, which was explicitly designed to exploit a vulnerability in FortiGate SSL-VPN gateways. The attackers possessed a functional exploit for CVE-2024-21762, a critical security flaw in FortiOS that allows an unauthenticated remote attacker to execute arbitrary code.
The presence of this toolkit at the mail.3bb.co[.]th gateway, which was running a vulnerable firmware version, strongly suggests that the attackers considered this a primary entry vector. However, cybersecurity analysts caution that while the intent was clearly present, the available forensic evidence does not conclusively prove that the FortiGate flaw was the actual "patient zero" for this specific breach. The possibility remains that the attackers gained initial access through other means, such as compromised third-party credentials or a separate, as-yet-undiscovered vulnerability.
Implications for Telecommunications Security
The 3BB incident serves as a stark reminder of the unique vulnerabilities faced by telecommunications infrastructure. Broadband providers are prime targets for state-sponsored and criminal actors alike because they sit at the intersection of critical national infrastructure and massive repositories of personal data.
The incident highlights several critical failures that are common across the industry:

- Shadow IT and Exposure: The existence of an open, unauthenticated server containing sensitive operational data is a significant security lapse that provided researchers with a roadmap of the attack.
- Trust in RMM Tools: The ease with which MeshCentral was repurposed into a persistent backdoor demonstrates that internal security policies must evolve to treat RMM tools as high-risk assets, requiring strict monitoring and multi-factor authentication.
- Supply Chain Risks: The potential impact on the Jasmine network illustrates the "blast radius" of interconnected corporate environments, where a breach at one entity can quickly become a systemic risk to partners and affiliates.
Industry Response and Mitigation
Upon discovery of the intrusion, Hunt.io adhered to standard responsible disclosure protocols, notifying both 3BB and the relevant national cybersecurity response agencies in Thailand. The attackers have since shuttered the exposed server, but the long-term impact remains uncertain. Because the persistence mechanisms (MeshCentral) are designed to be stealthy, it is unclear whether the attackers have been fully purged from the 3BB network or if they have pivoted to alternate, hidden channels of communication.
For organizations operating similar infrastructure, security experts recommend a rigorous audit of all remote management tools, an immediate review of VPN gateway firmware, and the implementation of stricter egress filtering. The shift toward "zero-trust" architectures, where every internal request is authenticated regardless of its origin, is no longer a luxury but a fundamental necessity for protecting subscriber privacy in the age of persistent, stealth-oriented threats.
As the digital landscape becomes increasingly complex, the 3BB case provides a vital case study in the necessity of proactive threat hunting. By moving beyond reactive defense and actively searching for indicators of compromise—such as the unauthorized deployment of RMM agents—organizations can identify and neutralize threats before they result in the catastrophic loss of user data or systemic network failure.







