Executive Summary

In June 2026, threat actors compromised 3BB, Thailand's largest broadband provider, using a sophisticated attack that leveraged CVE-2024-21762, a critical Fortinet FortiGate SSL-VPN vulnerability. The attackers maintained persistent access through MeshCentral remote management tools configured as hidden backdoors, achieved root-level privileges on internal servers, and targeted RADIUS databases containing subscriber credentials. Hunt.io researchers discovered the ongoing operation through an exposed attacker server containing tools, compromised device lists, and evidence of lateral movement across 3BB's network infrastructure.

This incident exemplifies the growing trend of attackers abusing legitimate remote management tools to maintain stealth persistence while exploiting unpatched edge devices for initial access, highlighting critical gaps in network segmentation and credential management practices.

Why This Matters Now

Telecommunications providers face intensified targeting as attackers seek subscriber data and network access for espionage campaigns, while the abuse of legitimate remote management tools like MeshCentral makes detection increasingly difficult for security teams.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used MeshCentral remote management software configured as hidden backdoors, with agents reporting to their control server at ayuthayatech[.]com under the device group TH-3BB.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained the attacker's lateral movement across 55+ systems and reduced the blast radius through workload segmentation and east-west traffic enforcement. The segmented architecture would likely have limited privilege escalation scope and controlled egress paths for data exfiltration attempts.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF architecture would likely have constrained the attacker's initial network reach by limiting access scope from the compromised SSL-VPN endpoint through segmented network boundaries

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely have limited the scope of privilege escalation by constraining administrative access to specific workload boundaries rather than broad server access

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have significantly reduced the attacker's ability to reach 55+ systems by enforcing segmented communication paths between workloads and blocking unauthorized SSH connections

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected and constrained the unauthorized MeshCentral agent's communication patterns to the external attacker infrastructure at ayuthayatech.com

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained the attacker's ability to exfiltrate RADIUS subscriber data by enforcing controlled outbound data flows and blocking unauthorized database extraction attempts

Impact (Mitigations)

With CNSF controls in place, the attacker's persistent access would likely be limited to isolated network segments, reducing the scope of potential subscriber data exposure and service disruption capabilities

Impact at a Glance

Affected Business Functions

  • Internet Service Provision
  • Customer Authentication Systems
  • Network Infrastructure Management
  • Customer Data Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

RADIUS authentication databases containing subscriber login credentials for broadband internet access, potential exposure of customer authentication data and network access credentials

Recommended Actions

  • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement across internal systems and limit SSH access to authorized workloads only
  • Deploy egress security controls with FQDN filtering to detect and block unauthorized outbound connections to attacker command and control infrastructure like MeshCentral servers
  • Enable multicloud visibility and anomaly detection to identify suspicious remote management tool deployments and unauthorized administrative access patterns
  • Implement inline IPS with Suricata signatures to detect and block CVE-2024-21762 FortiGate exploitation attempts and other known vulnerability exploits
  • Establish encrypted traffic inspection and east-west traffic monitoring to detect credential harvesting activities and unauthorized database access attempts

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image