top of page
Scheider_300x600.jpeg
nvidio_728x90.png
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Chinese-made routers sold worldwide found with hidden surveillance implants

  • Marijan Hassan - Tech Journalist
  • 5 hours ago
  • 2 min read

Security researchers have uncovered three backdoor-like surveillance implants embedded in the firmware of routers manufactured by Shenzhen Zhibotong Electronics, better known as ZBT, raising fresh concerns about the security of networking equipment sold around the world.



The findings, published by cybersecurity firm VulnCheck, reveal that several ZBT routers contain software capable of giving remote operators powerful control over affected devices. Because ZBT manufactures hardware for numerous brands and white-label customers, users may not realize that their routers were built by the Chinese manufacturer.


Three Hidden Implants Discovered

The investigation initially focused on a Zbtlink AX3000 router, where researchers discovered an implant dubbed ENDLESSDOORS. The software launches automatically when the router boots, connects to a command-and-control server and can execute arbitrary commands with root privileges.


VulnCheck subsequently examined older hardware and found two additional implants, named DARKLANTERN and SPEAKINGSTONE:


  • DARKLANTERN is particularly concerning because it exposes a service over UDP port 9992 that can accept commands from the internet without proper authentication. Researchers found that the mechanism could provide attackers with information about the device and potentially allow them to execute commands with root-level privileges.


  • SPEAKINGSTONE takes a different approach. According to researchers, the implant can establish outbound connections, potentially bypassing traditional firewall protections. Its capabilities include extracting network credentials, manipulating DNS settings and establishing reverse SSH tunnels, effectively giving a remote operator extensive control over the router.


Hidden Behind Multiple Brands

One of the biggest challenges is identifying affected equipment. ZBT sells hardware to other companies that distribute the products under their own names.


VulnCheck found the implants in devices sold under various brands, including Zbtlink and WiFlyer. Researchers also purchased a Deep Orange cellular router from a U.S. seller on Amazon and discovered that it was actually a white-labeled ZBT device running older firmware containing DARKLANTERN and SPEAKINGSTONE.


Researchers identified 203 internet-facing devices running DARKLANTERN across 22 countries during a recent scan, although that figure represents devices responding to their probe rather than the total number of affected routers worldwide.


Security teams are being urged to audit networking hardware, identify ZBT-based devices and consider replacing affected equipment rather than relying solely on firmware updates.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page