Interestana
Home/News/3BB Attacker Used MeshCentral Backdoor for Root Access
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

3BB Attacker Used MeshCentral Backdoor for Root Access

3BB Attacker Used MeshCentral Backdoor for Root Access

An unidentified attacker infiltrated the network of 3BB, a prominent broadband provider in Thailand, and established persistent remote access by exploiting a legitimate remote management tool known as MeshCentral. Threat intelligence firm Hunt.io disclosed this intrusion, detailing how the attacker leveraged a MeshCentral backdoor to achieve root-level privileges on internal machines. The firm's investigation began after discovering a server left exposed on the internet, which contained the attacker's own operational tools and a list of targeted credentials.

The attacker's methodology involved using MeshCentral, a web-based open-source remote management software, to maintain command and control over compromised systems within 3BB's infrastructure. This allowed the threat actor to move laterally and escalate privileges, ultimately aiming to exfiltrate sensitive subscriber data. MeshCentral is designed for legitimate remote administration of computers, but in this instance, it was weaponized by the attacker to bypass security measures and establish a covert presence. The specific vulnerability or misconfiguration within MeshCentral that enabled this backdoor access has not been publicly detailed by Hunt.io, but the firm confirmed the attacker achieved root access, indicating a deep level of compromise.

Hunt.io's analysis revealed that the attacker was actively targeting subscriber credentials, suggesting a motive of identity theft, fraud, or further network compromise. The presence of the attacker's tools on the exposed server provided Hunt.io with direct evidence of the intrusion and the attacker's operational methods. The firm has not yet attributed the attack to any specific threat group. The incident highlights the risks associated with the misuse of legitimate IT management tools, which can be repurposed by malicious actors to gain unauthorized access and maintain stealthy operations within targeted networks. The compromised nature of subscriber credentials poses a significant risk to 3BB's customer base, potentially leading to account takeovers and other forms of cybercrime.

This incident underscores the ongoing threat landscape faced by telecommunications companies, which are often prime targets due to the vast amounts of sensitive customer data they possess. The use of MeshCentral by the attacker demonstrates a sophisticated approach, as it leverages a tool that might already be present or accepted within an organization's IT environment, making detection more challenging. Hunt.io's proactive threat hunting and analysis were crucial in uncovering this deep-seated intrusion. Further details regarding the timeline of the compromise and the full extent of data exfiltration are still under investigation.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next