Chinese Routers Sold Worldwide Contain Backdoors
Chinese router manufacturer Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) has been selling routers containing multiple backdoors, some dating back a decade, to white-label distributors worldwide. These backdoors, including EndlessDoors, SpeakingStone, and DarkLantern, allow remote access and control of infected devices, potentially enabling espionage and data theft. Despite ZBT’s attempts to halt sales and release firmware updates, infected routers remain widely available on marketplaces like Amazon and Alibaba. The scope of the issue is difficult to determine, but estimates suggest potentially hundreds or even thousands of infected devices globally, particularly in countries like the US, Russia, and China. Organizations need to proactively identify ZBT-branded devices and consider replacing them.
Chinese router manufacturer Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) has been selling routers containing multiple backdoors, some dating back a decade, to white-label distributors worldwide. These backdoors, including EndlessDoors, SpeakingStone, and DarkLantern, allow remote access and control of infected devices, potentially enabling espionage and data theft. The issue was brought to light by Jacob Baines, CTO at VulnCheck, who discovered EndlessDoors, a decade-old Linux remote control tool, built into ZBT routers.
EndlessDoors initiates a connection to a strange domain, bypassing firewalls, to establish command-and-control (C2) communications, allowing an attacker to spy on user activity, steal credentials, or perform DNS hijacking. SpeakingStone, similar to EndlessDoors, initiates a connection to its controlling domain, sending system data including GPS coordinates and accepting arbitrary system-level commands, including DNS hijacking. DarkLantern is a listener, allowing an attacker to initiate a connection into an infected router, with ZBT explicitly designed to allow traffic to the UDP port the malware listens for, making it simple to exploit unless the device is otherwise protected by third-party firewalls.
ZBT responded to Baines’s findings by shutting down sales on Amazon and their website, and releasing firmware to remove the implants. However, infected routers remain available on marketplaces like Amazon and Alibaba, sold under innocuous brand names. Baines estimates that the number of infected devices is in the six figures, though accurately gauging the full scope is difficult due to white-labeling and tracing challenges.
Organizations need to proactively identify ZBT-branded devices by looking for specific hardware MAC addresses. Replacing these devices is recommended, though Baines notes that for some organizations, particularly those deploying ZBT routers in remote locations like oil pipelines for 4G/5G connectivity, this replacement process can be challenging.
At the end of the day, Baines advises sticking with trusted brands like Cisco and Ubiquiti. The issue highlights a significant risk of deploying potentially compromised hardware and underscores the importance of rigorous vendor vetting and supply chain security.
