← Back to Tech & Science

Thailand's 3BB Compromised by MeshCentral Backdoor Targeting Subscriber Data

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

BANGKOK — A sophisticated cyberattack on Thailand's third-largest mobile operator, Advanced Info Service Public Co., known as 3BB, has exposed a breach in which an intruder gained root-level access to critical subscriber databases. The incident, detected on Monday, September 14, 2026, involved the misuse of a legitimate remote management application called MeshCentral, which was repurposed as a hidden backdoor to maintain persistent access within the carrier's network.

Security analysis indicates the attacker utilized tools associated with the domain www.ayuthayatech[.]com to execute the intrusion. The intruder successfully established root privileges, allowing for deep system control and the ability to evade standard detection mechanisms. By embedding the MeshCentral agent into the infrastructure, the threat actor created a covert channel that remained undetected while targeting RADIUS (Remote Authentication Dial-In User Service) databases. These systems are essential for authenticating mobile subscribers, managing billing data, and controlling network access.

The attack vector highlights a growing trend of adversaries leveraging legitimate software to mask malicious activities. MeshCentral, an open-source remote management tool widely used by IT administrators for device monitoring, was installed on 3BB systems under the guise of routine maintenance. Once deployed, it served as a command-and-control interface, enabling the attacker to execute commands and exfiltrate data without triggering immediate alarms from traditional perimeter defenses.

The specific objectives behind the breach remain unclear. While the attacker demonstrated the capability to access sensitive subscriber information, no public confirmation has been made regarding whether data was stolen or if the intrusion was part of a broader reconnaissance effort. The involvement of tools linked to Ayuthaya Tech raises questions about the origin and affiliation of the threat actor, though no group has claimed responsibility for the incident.

3BB has initiated emergency containment procedures following the discovery of the unauthorized access. The carrier is working to isolate affected systems and remove the compromised MeshCentral agents from its network. Thai cybersecurity authorities have been notified and are coordinating with the telecommunications provider to assess the full scope of the breach and determine if customer data was exposed.

The incident underscores the vulnerabilities inherent in remote management tools when deployed without rigorous oversight. As mobile operators increasingly rely on cloud-based infrastructure, the line between administrative utility and security risk continues to blur. Investigators are currently examining the timeline of the intrusion to determine how long the attacker maintained access before detection.

Questions remain regarding the extent of data compromise and whether other systems within 3BB's network were targeted. The carrier has not yet released details on the number of subscribers potentially affected, leaving customers awaiting further updates as the investigation continues.

Discussion

0 / 2000