Incident
Published 2026-09-14
Verified 2026-09-19

3BB (Thailand ISP): Hunt.io finds MeshCentral backdoor, RADIUS targeting

Hunt.io (14 September 2026; The Hacker News same day) describes an intrusion against 3BB, a major Thai broadband provider. Researchers captured an attacker-operated server still live on 3 June 2026 that held tooling run from inside 3BB’s network, a MeshCentral deployment reporting to www.ayuthayatech[.]com under device group TH-3BB (agents with root), cleanup scripts that preserved MeshCentral, SSH password spraying against 55+ internal hosts, probes of agent.3bb.co[.]th, and scripts aimed at copying RADIUS subscriber credential databases (targeted; Hunt.io does not state confirmed exfiltration). The same cache held a complete exploit for FortiGate SSL-VPN CVE-2024-21762 aimed at mail.3bb.co[.]th and a valid 3BB VPN certificate plus Jasmine-network sessions (shared infrastructure; Jasmine breach not confirmed). Primary: Hunt.io; secondary: THN.

Product
3BB broadband network (FortiGate SSL-VPN; MeshCentral; RADIUS)
Versions
FortiGate firmware affected by CVE-2024-21762 reported on targeted gateway; MeshCentral abused as living-off-the-land C2
Exploited in Australia?
unknown
Patch to
ISPs/enterprises: patch FortiGate SSL-VPN (CVE-2024-21762 class); hunt unauthorized MeshCentral/RMM; rotate RADIUS and VPN credentials if similar tooling seen

Primary: Hunt.io — 3BB FortiGate / MeshCentral intrusion (14 Sep 2026) · CVE: CVE-2024-21762 · The Hacker News (14 Sep 2026)

breaches network identity