Particle.news
Download on the App Store

Zbtlink Routers Found to Ship With Factory-Installed Backdoor That Can Open Root Shells

Researchers warn the implant phones home to Chinese command servers, letting those servers run commands that give remote root access.

Overview

  • VulnCheck disclosed Thursday that every Zbtlink firmware image it reviewed contains an implant named ENDLESSDOORS that regularly beacons to specific Chinese command-and-control endpoints.
  • The implant is built from an open-source rctl tool, runs as a root userland process disguised as a kworker thread, and accepts commands without any authentication so a reserved string can spawn an interactive root shell.
  • Zbtlink has temporarily pulled affected firmware downloads and said it will deliver validated patches while telling a reporter the code was meant for after-sales maintenance, a claim VulnCheck and others publicly dispute.
  • Researchers advise replacing any affected device when possible or, at minimum, blocking egress to the listed C2 endpoints, isolating the router on an untrusted LAN, and scanning for indicators such as /usr/sbin/kworker, /usr/lib/librctl.so, and /etc/init.d/skworker.
  • The issue widens risk because many Chinese-made units are sold under different brands or supplied by ISPs, and outbound-initiated implants can be reached through normal NAT egress paths, which raises regulatory and network-security concerns.