Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware
Security researchers at Vulncheck discovered intentionally masked surveillance implants embedded in the firmware of numerous devices from Shenzhen Zhibotong Electronics.
Security researchers have discovered three backdoor-like implants embedded in the firmware of Chinese-made routers sold globally. The hardware, manufactured by Shenzhen Zhibotong Electronics (ZBT), goes by various brand names, making it difficult for users to identify. The research, conducted by VulnCheck, began with a Zbtlink AX3000 router and led to the discovery of an implant called ENDLESSDOORS.
This implant, which runs automatically at boot and disguises itself as a normal Linux kernel process, can execute arbitrary commands as root and connect to a command-and-control server. ENDLESSDOORS has been found in 20 ZBT models, including the Z8102AX, WG3526, and WE826-T3-DSIM. Additionally, the researchers uncovered two other implants, DARKLANTERN and SPEAKINGSTONE, in an older Deep Orange 4G/LTE Router.
DARKLANTERN, which operates as the infosrvd service, can be easily exploited to execute arbitrary commands as root. SPEAKINGSTONE, on the other hand, periodically beacons outbound to ZBT's command-and-control infrastructure, allowing remote operators to execute arbitrary commands, steal WAN PPPoE credentials, rewrite DNS lists, and establish reverse SSH tunnels.
The discovery highlights the potential for large-scale Chinese surveillance technology, as the majority of infected routers were located in China.
Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.