Chinese Routers Sold Worldwide Contain Backdoors
ID: f84a074e-fcaa-54c5-b196-aecddb0f2d34
STIX ID: report--f84a074e-fcaa-54c5-b196-aecddb0f2d34
Feed Name: Dark Reading
Research by VulnCheck CTO Jacob Baines revealed that Shenzhen Zhibotong (ZBT) white-label router firmware contains multiple persistent root-level backdoors—EndlessDoors, SpeakingStone, and DarkLantern—capable of outbound C2 beaconing, remote command execution, DNS hijacking, and inbound listener access; these implants appear across many rebranded routers sold globally, likely affecting at least hundreds and potentially six figures of devices, with observable indicators (sinkholed C2 connections, MAC OUI prefixes) and substantial remediation challenges due to white-labeling and remote deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
