mimile
Back to feed

VulnCheck Finds Backdoors in ZBT Routers Sold in Over 50 Countries

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

VulnCheck Finds Backdoors in ZBT Routers Sold in Over 50 Countries

VulnCheck CTO Jacob Baines revealed on Aug. 6 that Shenzhen Zhibotong Electronics (ZBT) routers contain root-level backdoors, including a decade-old Linux tool named EndlessDoors. The backdoors allow remote command-and-control with root privileges, potentially exposing user traffic and credentials. ZBT exports to more than 50 countries, with sales in the US, Canada, Germany, and Australia.

Key Facts

  • ZBT is the bestselling router manufacturer on Alibaba.com, with an annual output of 3.6 million units.
  • EndlessDoors, a decade-old open source Linux remote control tool, was found disguised as a kernel thread in ZBT firmware.
  • VulnCheck detected 203 instances of the DarkLantern backdoor exposed online over a three-day span.
  • ZBT routers have contained a variety of backdoors dating back several years, including SpeakingStone and DarkLantern implemented around 2019.

Backdoor Discovery

Jacob Baines, CTO of VulnCheck, found a decade-old open source Linux remote control tool called EndlessDoors in his home office router. EndlessDoors was disguised as a kernel thread for ordinary system processing and beaconed to a strange domain to establish command-and-control communications. The router was sold by Zbtlink, a ZBT brand, and EndlessDoors impacted dozens of router models. Baines then bought a router from DeepOrange, a New York-based company that sells ZBT technology under its own brand, and found two other backdoors named SpeakingStone and DarkLantern. These backdoors appeared to be earlier versions of EndlessDoors, implemented in ZBT firmware around 2019.

DarkLantern Exposure

DarkLantern is a listener backdoor that allows ZBT or an attacker with its C2 infrastructure to initiate a connection into an infected router. ZBT boxes are explicitly designed to allow traffic to the UDP port the malware listens for, making the task simple unless protected by third-party firewalls. In a three-day span, VulnCheck detected only 203 instances of the DarkLantern backdoor exposed online.

1 source

VulnCheck Finds Backdoors in ZBT Routers Sold in Over 50 Countries