A massive cybersecurity investigation has revealed that ZBT routers, sold globally under various brand names, contain multiple manufacturer-installed backdoors for remote spying.

  • ZBT routers contain multiple implants including 'EndlessDoors', 'SpeakingStone', and 'DarkLantern'.
  • These devices are sold as white-label products in over 50 countries, including the US, India, and Germany.
  • Experts estimate the number of infected devices could be in the hundreds of thousands.
  • A major cybersecurity investigation has uncovered that Shenzhen Zhibotong Electronics Co. Ltd. (ZBT), a leading Chinese manufacturer, has been embedding malicious backdoors into routers sold globally. These devices are often sold as 'white-label' products, meaning various international companies buy the technology and sell it under their own brand names, making the source of the threat incredibly difficult to trace.

    The Anatomy of the Malware: EndlessDoors and More

    Jacob Baines, CTO of VulnCheck, discovered that the most recent firmware contains a root-level backdoor known as 'EndlessDoors'. This tool disguises itself as a standard system process but beacons out to external command-and-control domains to allow remote access. Further investigation revealed two other implants: 'SpeakingStone', which exfiltrates system data and GPS coordinates, and 'DarkLantern', a listener that allows attackers to initiate connections directly into a user's network.

    The white-labeling and difficulty of tracing these devices makes it incredibly hard to gauge the true scale of the infection.

    Why This Matters: A Global Security Crisis

    BozokMedia analysis shows that this is not just a localized issue but a systemic threat to global digital infrastructure. With ZBT producing millions of units annually and exporting to more than 50 countries, the potential for massive data breaches, credential theft, and state-sponsored espionage is unprecedented. The ability for an attacker to gain root-level privileges through a home or office router means the entire internal network is compromised.

    Historical Context: The Supply Chain Threat

    For years, concerns regarding Chinese-made hardware in critical infrastructure have persisted. ZBT, a 15-year-old company and a top seller on Alibaba.com, represents the massive scale at which these vulnerabilities can be distributed. While the company has attempted to release patched firmware, researchers found that unpatched, infected units are still being sold on major marketplaces like Amazon.

    Did You Know?: These backdoors often use 'outbound' connections, meaning the router initiates contact with the hacker, allowing it to bypass most traditional incoming firewalls.

    Frequently Asked Questions

    1. How can I identify if my router is a ZBT product?
    Check the MAC address of your device; specific ranges are allocated specifically to ZBT.

    2. Is updating the firmware enough?
    Not necessarily. Researchers have found that even after patches were released, unpatched devices continued to appear in the market under different brand names.

    Original Source Link (Dark Reading)