SECURITY Signal 71
Three distinct firmware implants discovered in ZBT routers sold globally
VulnCheck identified three separate backdoor-like implants, ENDLESSDOORS, DARKLANTERN, and SPEAKINGSTONE, embedded in the firmware of routers manufactured by Shenzhen Zhibotong Electronics and sold under many brands worldwide.
The implants give remote attackers root-level control, can exfiltrate credentials, rewrite DNS settings, and operate even behind NAT, posing a severe security risk for networks that use these devices. Engineers must treat affected ZBT models as compromised, update firmware where possible, and consider replacing them to prevent unauthorized access.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ENDLESSDOORS runs as a disguised kernel process, contacts a hard-coded command-and-control server, and executes arbitrary root commands.
DARKLANTERN opens an unauthenticated UDP listener on port 9992, allowing any internet host to query device info and run commands as root.
SPEAKINGSTONE beacons outbound over UDP port 10000, can steal PPPoE credentials, modify DNS, and establish reverse SSH tunnels even when the router is behind a firewall.
THE CLUSTER
↗