A Chinese router manufacturer has been secretly installing backdoors in its products, which are sold worldwide under various brand names. The vulnerabilities, discovered by cybersecurity researcher Jacob Baines, allow attackers to gain root-level access to routers and potentially compromise entire networks.
Shenzhen Zhibotong Electronics Co. Ltd., also known as ZBT, is one of the largest router manufacturers globally, selling over 3.57 million units annually through online marketplaces like Alibaba.com. The company exports its products to more than 50 countries, including the US, Canada, Australia, and several European nations. However, it appears that many of these routers contain malicious code designed to facilitate unauthorized access.
Baines’ investigation began when he discovered a decade-old Linux remote control tool called “EndlessDoors” embedded in his own ZBT router. Disguised as a kernel thread for system processing, EndlessDoors initiates a connection to a mysterious domain whenever the router is powered on. This allows an attacker to establish command-and-control communications and potentially gain root-level access to the device.
Further analysis revealed that multiple versions of the backdoor exist, with some dating back several years. For instance, two other implants, “SpeakingStone” and “DarkLantern,” were found in a different ZBT router model purchased by Baines on Amazon. These backdoors appear to be earlier iterations of EndlessDoors, implemented in 2019.
The DarkLantern listener is particularly concerning as it allows an attacker to initiate a connection into the infected router. This can be done through a simple UDP port request, unless the device is protected by third-party firewalls. In a three-day span, VulnCheck detected only 203 instances of the DarkLantern backdoor exposed online, with most connections originating from countries like the US, Russia, and China.
SpeakingStone is more versatile as it initiates a connection out to its controlling domain, sending system data and accepting arbitrary commands. However, Baines was able to sinkhole the C2 domain associated with this implant, rendering it useless for attackers.
While the number of affected routers may be in the hundreds, the sheer scale of ZBT’s global sales makes this a significant concern. If left unaddressed, these backdoors could allow widespread network compromise and data theft. As Baines notes, “Chinese backdoors in network technologies has always been something of a stereotype, but perhaps never been this blatant.”
In light of this discovery, it is essential for users to take immediate action to secure their networks. First and foremost, they should replace any ZBT router with an equivalent product from a reputable manufacturer. Furthermore, all devices connected to the network should be checked for signs of unauthorized access or malicious activity. Finally, users are advised to enable robust firewall protection and implement regular security updates to minimize the risk of exploitation. By taking these precautions, individuals can safeguard their networks against potential attacks facilitated by compromised routers.
Source: Dark Reading — 2026-08-27