started · updated
Zbtlink routers found with embedded spyware component
Security researchers at VulnCheck have identified a malicious component, dubbed ‘ENDLESSDOORS’, embedded in certain router models sold under multiple brands. The vulnerability was discovered in the Zbtlink AX3000 Dual SIM 5G CPE WiFi 6 router, which was found to be making unauthorized connections to external servers despite being on an isolated research network.
The hardware is manufactured by Shenzhen Zhibotong Electronics and is distributed as an OEM or ODM product to various brands, including Zbtlink and Wiflyer. The implant uses a modified version of the ‘rctl’ tool to function as both a client and server, allowing for remote Linux control. Because the device initiates the outbound connection, it can bypass firewalls and NAT settings.
Researchers demonstrated that the implant, which hides among processes named ‘kworker’, allows an attacker to gain interactive shell access with root privileges. The communication does not require client or server verification, meaning an attacker can send commands to the device once a connection is established.
Entities
Alibaba · MIT Media Lab · Shenzhen Zhibotong Electronics · VulnCheck · Zbtlink