Thailand Broadband Intrusion Exposed via Left-Open Server

An attacker maintained hidden control over 3BB's internal network using a legitimate management tool, aiming to steal customer credentials.
A threat actor operated undetected within the network of 3BB, one of Thailand’s largest broadband providers, by leveraging a standard IT management tool as a covert backdoor. The intrusion was discovered when researchers identified a server the attacker had mistakenly left accessible on the public internet. This exposed machine contained the attacker’s own tools and a registry of internal systems already under their control, revealing the scale of the compromise.
According to Hunt.io, the attacker installed MeshCentral, a free software typically used by IT teams for remote administration, to maintain persistent access. By configuring it to report to an external control server, the attacker created a hidden channel that blended in with routine network management traffic. This approach allowed them to retain full administrative rights on internal servers even after other traces of the intrusion were cleaned up.
Legitimate Tooling Masked Malicious Intent
The decision to use MeshCentral highlights a significant trade-off in modern IT security. While such tools offer convenient remote access, their trusted status means their network activity often bypasses suspicion. Security teams may overlook connections to these servers as normal administrative tasks, giving attackers a durable foothold. In this case, the attacker deliberately preserved the MeshCentral agent during cleanup efforts to ensure this access survived any defensive scrubbing of the system.
Recovered files showed the attacker had achieved root-level privileges on multiple internal machines. The configuration pointed to a specific device group, indicating a targeted and organized operation rather than opportunistic scanning. This method of persistence is difficult to detect because it relies on legitimate software signatures that are usually whitelisted by security filters.
Targeting Customer Authentication Systems
The primary objective of the intrusion appears to have been the theft of subscriber credentials. Scripts found on the exposed server were designed to extract data from RADIUS databases, which store the login information broadband customers use to access the internet. The presence of these tools suggests a direct effort to compromise user accounts, although researchers noted there is no evidence that the data was actually exfiltrated.
The attacker also sought to expand their reach within the infrastructure. They probed internal sales portals and attempted to brute-force passwords on over 55 internal computers. Additionally, the toolkit included mechanisms to plant web shells and install unauthorized SSH keys, providing multiple redundant pathways to regain access if one method failed. This broadening of access indicates an intent to establish a long-term presence within the corporate network.
Unconfirmed Entry Point and Risks
While the exact method of initial entry remains unclear, the attacker possessed a complete exploit for a serious vulnerability in Fortinet’s FortiGate SSL-VPN gateway. The targeted device was running an affected firmware version, making it a plausible entry point. However, the presence of the exploit code does not confirm it was successfully used. It may have been part of a broader toolkit aimed at various entry vectors, leaving the initial breach point unverified.
The situation carries ongoing risks for both 3BB and its former parent company, Jasmine. The attacker held valid VPN certificates and active sessions for services on the Jasmine network, suggesting a potential cross-infrastructure threat. Although the exposed server has since been closed, the lack of confirmation regarding current access levels means the intrusion may still be active. Organizations are advised to verify patches for known vulnerabilities and audit the use of remote management tools to mitigate similar risks.






