started · updated
Zbtlink routers found to contain surveillance backdoors
Cybersecurity researchers at VulnCheck have identified two new surveillance backdoors, named ‘Speakingstone’ and ‘Darklantern’, in routers manufactured by Zbtlink (Shenzhen Zhibotong Electronics). These vulnerabilities were discovered in hardware sold through major platforms like Amazon, including devices sold by U.S. sellers.
The ‘Speakingstone’ program can redirect internet traffic, obtain login credentials, and take control of devices by communicating with remote servers. The ‘Darklantern’ vulnerability allows unauthorized users to gain control of an affected router without a password.
Researchers observed these programs actively operating in the field. In one instance, 392 routers contacted a researcher-registered address, with 390 of those located in China, many of which were connected via China Mobile. These findings follow a previous investigation into the ‘ENDLESSDOORS’ backdoor found in over 20 Zbtlink router models worldwide.
Entities
China Mobile · Shenzhen Zhibotong Electronics · VulnCheck · Zbtlink