A massive cybersecurity investigation has revealed that ZBT routers, sold globally under various brand names, contain multiple manufacturer-installed backdoors for remote spying.
A major cybersecurity investigation has uncovered that Shenzhen Zhibotong Electronics Co. Ltd. (ZBT), a leading Chinese manufacturer, has been embedding malicious backdoors into routers sold globally. These devices are often sold as 'white-label' products, meaning various international companies buy the technology and sell it under their own brand names, making the source of the threat incredibly difficult to trace.
The Anatomy of the Malware: EndlessDoors and More
Jacob Baines, CTO of VulnCheck, discovered that the most recent firmware contains a root-level backdoor known as 'EndlessDoors'. This tool disguises itself as a standard system process but beacons out to external command-and-control domains to allow remote access. Further investigation revealed two other implants: 'SpeakingStone', which exfiltrates system data and GPS coordinates, and 'DarkLantern', a listener that allows attackers to initiate connections directly into a user's network.
The white-labeling and difficulty of tracing these devices makes it incredibly hard to gauge the true scale of the infection.
Why This Matters: A Global Security Crisis
BozokMedia analysis shows that this is not just a localized issue but a systemic threat to global digital infrastructure. With ZBT producing millions of units annually and exporting to more than 50 countries, the potential for massive data breaches, credential theft, and state-sponsored espionage is unprecedented. The ability for an attacker to gain root-level privileges through a home or office router means the entire internal network is compromised.
Historical Context: The Supply Chain Threat
For years, concerns regarding Chinese-made hardware in critical infrastructure have persisted. ZBT, a 15-year-old company and a top seller on Alibaba.com, represents the massive scale at which these vulnerabilities can be distributed. While the company has attempted to release patched firmware, researchers found that unpatched, infected units are still being sold on major marketplaces like Amazon.
Frequently Asked Questions
1. How can I identify if my router is a ZBT product?
Check the MAC address of your device; specific ranges are allocated specifically to ZBT.
2. Is updating the firmware enough?
Not necessarily. Researchers have found that even after patches were released, unpatched devices continued to appear in the market under different brand names.