Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)

Attacker Maintains Root-Level MeshCentral Backdoor Inside (TL-2026-2514) is a high-severity data breach scored CVSS 9.8, first published 2026-09-15. It has no confirmed attribution, affects Fortinet FortiOS / FortiProxy SSL-VPN, references 4 CVEs (CVE-2024-21762, CVE-2020-1938, CVE-2016-5195), maps to 18 MITRE ATT&CK techniques (T1005, T1021.004, T1046), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2514

Threat ID
TL-2026-2514
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-15
Last reviewed
2026-09-15
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, internet-service-provider, broadband
Target regions
Southeast Asia, thailand
Detection rules
9
Indicators of compromise
24

Malware and tooling in Attacker Maintains Root-Level MeshCentral Backdoor Inside

Malware and tooling: Dirty COW exploit (CVE-2016-5195), MeshCentral, PwnKit exploit (CVE-2021-4034)

Hunt.io discovered an exposed attacker staging server (92.63.180.133:8888) revealing an active, root-level intrusion inside Thai broadband provider 3BB (Triple T Broadband), where MeshCentral remote-management software was repurposed as a hidden backdoor reporting to www.ayuthayatech.com. The attacker used the confirmed CVE-2020-1938 (Ghostcat) flaw to gain root on an internal Pentaho/Tomcat server, password-sprayed SSH across 55+ hosts, and staged scripts to exfiltrate 3BB's RADIUS subscriber-credential databases (radius_corp, radiusinfo, job_radius); a complete but unconfirmed CVE-2024-21762 FortiGate SSL-VPN exploit kit was also found staged against 3BB's own gateway.

How Attacker Maintains Root-Level MeshCentral Backdoor Inside works

In June 2026, threat-intelligence firm Hunt.io identified an open directory at 92.63.180.133:8888, hosted on Bangmod Enterprise infrastructure, belonging to an attacker actively operating inside the network of 3BB (Triple T Broadband), one of Thailand's largest broadband ISPs. The directory held 298 files across 30 subdirectories (19MB total) and functioned as the attacker's operational staging area while the intrusion remained live.

Recovered artifacts show the attacker achieved root-level command execution on at least one internal Linux application server by exploiting CVE-2020-1938 ("Ghostcat"), an Apache Tomcat AJP-connector file-read/inclusion flaw, against a Pentaho BI/Tomcat service at 10.11.152.4:8009. To maintain long-term access, the attacker deployed MeshCentral -- a legitimate open-source remote-management platform -- configured as a hidden backdoor (config file meshagent.msh, device group "TH-3BB") with agents running as root on multiple compromised hosts and reporting to a command server at www.ayuthayatech.com over port 443. A devices.json inventory recovered from the staging server catalogued enrolled hosts by hostname, IP, OS, and privilege level.

The attacker's primary objective centered on 3BB's RADIUS infrastructure: a recovered script (db_creds.sh) was purpose-built to copy out databases named radius_corp, radiusinfo, and job_radius -- the systems that store broadband-subscriber authentication credentials. Supporting tooling recovered from the staging server included SSH password-spraying utilities run against 55+ internal systems (using common passwords plus organization-specific combinations), a credential-harvesting script (cred_hunt.sh) targeting SSH private keys, PHP configuration files, database passwords, SNMP community strings, and command histories, a PHP web shell (/var/www/html/info.php) deployed via MySQL abuse, and local privilege-escalation exploits for CVE-2016-5195 (Dirty COW) and CVE-2021-4034 (PwnKit), plus a concealed SUID backdoor at /usr/local/bin/.rc. An anti-forensic cleanup script (cleanup_target.sh) deleted exploitation files, web shells, authentication/system logs, and shell histories -- while deliberately preserving both the MeshCentral agent and the hidden SUID backdoor, indicating the actor planned to retain access after cleanup.

The staging server also held a complete exploit toolkit for CVE-2024-21762, a critical (CVSS 9.8) unauthenticated out-of-bounds write in FortiOS/FortiProxy SSL-VPN, targeting 3BB's own FortiGate 60F gateway at mail.3bb.co.th:10443. Eight reconnaissance scripts fingerprinted the VPN service, inspected HTTP headers, and probed for historical vulnerabilities using controlled crashes and malformed chunked HTTP requests; a further stage combined heap spraying with an ROP chain intended to launch a reverse shell to the staging server's port 9443, and the attacker sought FortiOS 7.2.5 firmware to derive model/version-specific ROP gadgets. Hunt.io found no evidence this exploit chain was ever executed against the live gateway.

Additional recovered artifacts point to broader targeting: probing of the internal CodeIgniter-based sales/agent portal (agent.3bb.co.th, behind an F5 BIG-IP at 110.164.192.228) for authentication bypass, session forgery, file upload, SQL injection, path traversal, SSRF, and HTTP request smuggling; and an OpenVPN profile (jasmine.ovpn) containing a certificate and private key issued under 3BB's own PKI for a formerly-affiliated "Jasmine" network entity (VPN endpoint 110.164.129.67:443), with evidence of active login sessions -- suggesting concurrent targeting of that adjacent infrastructure. No threat-actor attribution was published. Hunt.io notified 3BB and relevant national cybersecurity response teams prior to public disclosure on 2026-09-14.

MITRE ATT&CK techniques used in TL-2026-2514

Collection

T1005 Data from Local System

Lateral Movement

T1021.004 SSH

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery

Execution

T1059.004 Unix Shell

Stealth

T1070.003 Clear Command History

Command and Control

T1071.001 Web Protocols; T1219 Remote Access Tools

Persistence

T1078 Valid Accounts; T1505.003 Web Shell

Credential Access

T1110.003 Password Spraying; T1552.001 Credentials In Files; T1552.004 Private Keys

Initial Access

T1190 Exploit Public-Facing Application

Privilege Escalation

T1548.001 Setuid and Setgid

Resource Development

T1588.005 Exploits

Reconnaissance

T1595.002 Vulnerability Scanning

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in Attacker Maintains Root-Level MeshCentral Backdoor Inside

  • Fortinet — FortiOS / FortiProxy SSL-VPN
    Vulnerable versions: 6.0.0-6.0.17; 6.2.0-6.2.15; 6.4.0-6.4.14; 7.0.0-7.0.13; 7.2.0-7.2.6; 7.4.0-7.4.2
    Fixed in: See Fortinet PSIRT FG-IR-24-015 for the fixed release per branch
  • 3BB / Triple T Broadband — FortiGate 60F SSL-VPN gateway (mail.3bb.co.th)
    Vulnerable versions: Attacker toolkit targeted FortiOS 7.2.5-era firmware; exploitation against this device unconfirmed
  • Apache — Apache Tomcat AJP Connector (internal Pentaho BI Server deployment) — CVE-2020-1938 / Ghostcat
    Vulnerable versions: Tomcat < 9.0.31; Tomcat < 8.5.51; Tomcat < 7.0.100
    Fixed in: 9.0.31+; 8.5.51+; 7.0.100+
  • Linux kernel — Copy-on-write memory subsystem — CVE-2016-5195 / Dirty COW (recovered local privilege-escalation exploit)
    Vulnerable versions: Kernel versions prior to the October 2016 fix
    Fixed in: Patched kernel releases from October 2016 onward
  • polkit — pkexec — CVE-2021-4034 / PwnKit (recovered local privilege-escalation exploit)
    Vulnerable versions: All polkit releases prior to the May 2021 patch
    Fixed in: Patched releases from May 2021 onward

Remediation for Attacker Maintains Root-Level MeshCentral Backdoor Inside

Patches

  • Fortinet PSIRT FG-IR-24-015 (CVE-2024-21762)
  • Apache Tomcat 9.0.31+ / 8.5.51+ / 7.0.100+ (CVE-2020-1938)
  • Linux kernel copy-on-write race-condition patch (CVE-2016-5195)
  • polkit pkexec patch (CVE-2021-4034)

Immediate actions

  • Patch/upgrade all FortiGate SSL-VPN appliances per Fortinet PSIRT advisory FG-IR-24-015 and confirm the mail.3bb.co.th gateway is on a fixed FortiOS build
  • Hunt for and remove unauthorized MeshCentral agents reporting to www.ayuthayatech.com; treat any RMM client not deployed by IT as a hostile backdoor
  • Hunt for and remove hidden SUID binaries such as /usr/local/bin/.rc across all Linux hosts
  • Rotate all RADIUS/subscriber credentials and force re-enrollment given confirmed targeting of the radius_corp, radiusinfo, and job_radius databases
  • Revoke and reissue the OpenVPN certificate/key pair referenced in the recovered jasmine.ovpn profile

Workarounds

  • Disable SSL-VPN on FortiGate devices where immediate patching is not possible
  • Disable or restrict the AJP connector to localhost if not required

Longer-term hardening

  • Disable or restrict the Tomcat AJP connector on Pentaho/BI deployments per CVE-2020-1938 (Ghostcat) guidance
  • Enforce SSH key-based authentication with account lockout/rate-limiting to blunt password-spray campaigns
  • Deploy EDR/host-integrity monitoring capable of detecting SUID abuse, hidden RMM agents, and unauthorized web shells
  • Segment RADIUS and subscriber-credential database systems from general application/web-tier network segments

CVEs associated with Attacker Maintains Root-Level MeshCentral Backdoor Inside

CVE-2024-21762, CVE-2020-1938, CVE-2016-5195, CVE-2021-4034

Weaknesses (CWE) in Attacker Maintains Root-Level MeshCentral Backdoor Inside

CWE-787

Timeline of Attacker Maintains Root-Level MeshCentral Backdoor Inside

  • Fortinet discloses CVE-2024-21762, a critical (CVSS 9.8) out-of-bounds write in FortiOS/FortiProxy SSL-VPN enabling unauthenticated remote code execution (PSIRT FG-IR-24-015).
  • CISA adds CVE-2024-21762 to the Known Exploited Vulnerabilities catalog, citing confirmed in-the-wild exploitation.
  • cleanup_target.sh recovered, showing deletion of exploitation files, web shells, and logs/histories while deliberately preserving the MeshCentral agent and hidden SUID backdoor at /usr/local/bin/.rc.
  • A complete but unconfirmed CVE-2024-21762 exploit chain (VPN fingerprinting, heap-spray/ROP reverse-shell stage) is found staged against 3BB's own FortiGate 60F gateway at mail.3bb.co.th:10443.
  • Recovered db_creds.sh script found purpose-built to copy out the radius_corp, radiusinfo, and job_radius subscriber-credential databases.
  • Staging server contains meshagent.msh configuration for device group "TH-3BB" reporting to www.ayuthayatech.com:443, confirming MeshCentral deployed as a hidden root-privileged backdoor across multiple compromised hosts.
  • Recovered artifacts show CVE-2020-1938 (Ghostcat) used against the internal Pentaho/Tomcat AJP service at 10.11.152.4:8009, achieving root-level command execution on the application server.
  • Hunt.io first indexes the attacker's open directory at 92.63.180.133:8888 (298 files, 30 subdirectories, 19MB), hosted on Bangmod Enterprise infrastructure, with the intrusion still active.
  • Hunt.io publishes findings via The Hacker News after notifying 3BB and relevant national cybersecurity response teams.

Sources cited for Attacker Maintains Root-Level MeshCentral Backdoor Inside

More in data breach

Detection coverage for TL-2026-2514

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2514 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats